Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39753] Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions.
Unauthenticated Privilege Escalation in Taskbot
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39746] Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions.
Unauthenticated SQL Injection in Booknetic
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-32579] Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-32557] Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions.
Unauthenticated SQL Injection in WooCommerce Appointments
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-32568] Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions.
Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-94293] An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH req…
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105778] A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unkno…
A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105484] A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted el…
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-82989] There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a r…
There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105763] Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, …
Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords, because the field was not hidden and the lookup did not enforce the calling user's identity or accoun…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105697] Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.…
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/serv…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105740] Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any a…
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediate…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105691] Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places a…
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's pri…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-97283] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager adva…
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105638] Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the con…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105639] Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logge…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer u…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105640] Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses return…
Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to th…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105641] Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and …
Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community de…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105636] Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/a…
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. …
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105637] Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in ap…
Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, dr…