Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-104081] KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function wit…
KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass can be bypassed using crafted filenames like "....//", combined with PclZip's extract() call in KodArchive.class.php lacking the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option. Authenticated attackers can u…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-103412] Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apac…
Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any locat…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-94664] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Path Traversal.This issue affects PDF for Contact Form 7: from n/a through 7.1.0.
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-94666] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zeal…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1.
M Crítico vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107935] A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-ta…
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-84247] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial of s…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
M Crítico vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-75875] IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traversal.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-82900] IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to delete arbitrary file…
IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to delete arbitrary files due to improper limitation of a pathname to a restricted directory.
M Alto vulnerabilidad Nuevo
Hace 20 horas
[CVE-2026-19493] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-84275] IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionali…
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.
M Alto vulnerabilidad Nuevo
Hace 23 horas
[CVE-2026-107377] datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.8…
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_missing_weak_imports in src/datamodel_code_generator/parser/protobuf.py. Exploitation requires a victim or automated job to process the attacker-controlled…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107709] A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerabili…
A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitra…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-105816] Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference …
Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. This vulnerability (CVE-2026-105816) is …
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106557] Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @back…
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106560] Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugi…
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-102257] A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows a…
A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-103360] IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv…
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106486] Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-…
Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An authenticated user who can execute an eligible template and influence an allowed Bitb…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-101153] On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vul…
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-101154] An authenticated remote attacker with specific permissions can read or write files on the platform f…
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.