Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Ui" — 96 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 3 horas
Vulnerabilidad alta de autorización en StylemixThemes Motors permite eludir controles de acceso
StylemixThemes Motors versiones hasta 1.4.108 contiene una vulnerabilidad de autorización faltante que permite a atacantes eludir mecanismos de control de acceso incorrectamente configurados. Esta falla expone sitios web de agencias automotrices y concesionarios en México y LATAM a acceso no autorizado a funciones administrativas. El CVSS 7.5 indica riesgo alto que requiere atención inmediata.
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-101920] The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPres…
The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'comment (href attribute inside comment content)' parameter in all versions up to, and including, 5.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra…
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-100147] The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored…
The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shipping_first_name' parameter in all versions up to, and including, 3.16.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-96558] The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to S…
The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to, and including, 11.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene…
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-96682] The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Cont…
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Tag in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires…
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-104723] The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable t…
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via deserialization of untrusted input . This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vuln…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-104021] The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to,…
The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before in…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-107838] RIOT is an open-source microcontroller operating system designed for Internet of Things devices and …
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoA…
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-107813] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster r…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecureSession. An authenticated OTP-enabled user possessing a stolen or persisted JWT can therefore perform node CRUD, read or replace node credentials, chang…
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-107807] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts …
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment …
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-107808] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login c…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the pa…
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-107809] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired acce…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not universally require a CSRF token or perform Origin or Referer validation, a remote attacker can induce a logged-in administrator's browser to submit authenti…
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-107810] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/r…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx configuration path. An authenticated user who can create and restore backups can craft a valid backup that places a symlink in the staging tree and then writes…
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-107811] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenti…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth…
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-107812] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade …
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attacker able to alter both responses can supply a malicious executable and matching digest. An operator-triggered upgrade is required, and the application in…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-104084] SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and ref…
SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the …
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-104082] SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker…
SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker holding a SysAdmin-scoped access token to bypass the Volume Mount script-directory containment control by provisioning a new mail domain with an arbitrary FileStore root path inside the trusted Scripts directory via the domain-put endpoint. Attackers can disclose the Scripts path through the AddOrU…
M Alto vulnerabilidad Nuevo
Hace 20 horas
[CVE-2026-39460] Usernames and passwords, including the default factory credentials, are stored in plaintext within t…
Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication.
M Alto vulnerabilidad Nuevo
Hace 20 horas
[CVE-2026-29797] No authentication is required when updating firmware or bootloader, making it easy for malicious fil…
No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.
M Alto vulnerabilidad Nuevo
Hace 20 horas
[CVE-2026-107805] Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signatur…
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume tempo…