Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "X" — 3560 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107703] @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that…
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107704] The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in I…
The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby pr…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107699] ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execut…
ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-95210] Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates cont…
Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-9209] mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Logi…
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attacke…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-93034] SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder uncondit…
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled wi…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-14269] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker could overflow the buffer and execute arbitrary code on the system.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-14991] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-15762] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-16340] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-19218] Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Impo…
Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. MyRezzta allows Password Recovery Exploitation. This issue affects MyRezzta: from 2.06.03 before 2.07.01.
M Crítico vulnerabilidad
Hace 1 día
Vulnerabilidad crítica en AKINSOFT WOLVOX permite extracción de datos sensibles del sistema
Se ha identificado una vulnerabilidad de inserción de información sensible en el Panel de Control de AKINSOFT WOLVOX (versiones 26.02.25 anteriores a 26.02.26) que permite a atacantes extraer datos de recursos del sistema. Esta falla afecta principalmente a empresas de importación-exportación en México y Latinoamérica que utilizan esta solución para gestión operativa. El score CVSS de 9.1 indica severidad crítica.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-105110] OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an una…
OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-85097] The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versi…
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a …
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-107459] The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated r…
The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-103646] The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logg…
The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, includi…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76268] In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access t…
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration op…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76501] A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (…
A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM and SR…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76485] A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS…
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker c…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76486] A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS…
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker c…