Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 2785 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad alta de Directory Traversal en Plugin Product Designer App para WordPress (CVE-2026-75098)
El plugin Product Designer App para WordPress en versiones hasta 1.1.3 es vulnerable a Directory Traversal a través del parámetro 'svg', permitiendo a atacantes no autenticados leer archivos arbitrarios del servidor. Esta vulnerabilidad expone información sensible como credenciales de bases de datos, archivos de configuración y datos de usuarios en tiendas virtuales y sitios corporativos. El ataque requiere solo acceso a internet sin credenciales válidas, representando riesgo alta para e-commerce y plataformas en LATAM.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-75823] The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned …
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained …
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103102] Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation …
Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103106] Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation with…
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the o…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103054] AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that a…
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95315] Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potential…
Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95298] Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potent…
Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-92369] TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in…
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of th…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84783] Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause i…
Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certifi…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84784] Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames …
Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also with…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102360] A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-r…
A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. `readUint8Array` never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document c…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100831] Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Fir…
Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102496] Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema …
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
M Alto vulnerabilidad
29/09/2026
Falta de autenticación en Progress Fiddler Everywhere 8.0.2 permite acceso no autorizado a tokens OAuth
Progress Software Fiddler Everywhere 8.0.2 presenta una vulnerabilidad alta (CVSS 7.7) que permite a un atacante local sin credenciales acceder al backend .NET (Fiddler.WebUi) a través de canales HTTP y SignalR no autenticados. Esto posibilita la generación de tokens OAuth fraudulentos y la lectura del certificado raíz man-in-the-middle. Afecta principalmente a desarrolladores y equipos de testing que utilizan esta herramienta en México y Latinoamérica para análisis de tráfico HTTPS.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102248] A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of t…
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización en REBUILD hasta v4.4.11 permite acceso no autorizado remoto
Se ha identificado una falla de seguridad en REBUILD versiones hasta 4.4.11 que afecta el módulo /commons/file-editor-save, permitiendo omitir controles de autorización mediante manipulación de parámetros (url/fileKey). Esta vulnerabilidad de severidad alta (CVSS 7.3) puede ser explotada remotamente y su código de ataque ya es público. Empresas en LATAM que usan REBUILD para gestión de contenidos están expuestas a acceso no autorizado a archivos sensibles.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96326] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101860] A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the functio…
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102281] Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0…
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled non-string pattern to JSON.stringify to derive the handler lookup key; sufficiently de…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-18413] The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small…
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The NXP MCUX LPADC driver did not honour that contract. mcu…