Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Perl" — 489 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-45117] MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not…
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is available. install/index.php processes the values with addcslashes(), but the $characters argument added in MyBB 1.8.13 does…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-50575] BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly inv…
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75627] Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unaut…
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-11801] The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all…
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including register…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75111] Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoi…
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to access system files, which are then materialized into datasets and retrieved through the download endpoint.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-66795] A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto…
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enab…
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-71472] A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such a…
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/08/2026
[CVE-2026-46345] compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 a…
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`, `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the iss…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16471] Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Fun…
Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16467] Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing F…
Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74801] SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-lin…
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.
M Alto vulnerabilidad
16/08/2026
[CVE-2024-58375] OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when u…
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of…
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad alta de evasión de autorización en WP Travel Engine (CVE-2026-17087)
El plugin WP Travel Engine para WordPress (versiones ≤6.8.4) permite a atacantes no autenticados acceder a datos privados de reservas y facturación de clientes mediante evasión de controles de autorización. Esta vulnerabilidad afecta directamente a agencias de viajes, operadores turísticos y plataformas de booking en LATAM que utilizan este plugin para gestionar reservaciones y pagos.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73042] SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing…
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73046] SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middl…
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure counter used by the cookie/session login path. This all…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-19188] A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gate…
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands w…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19768] Improper control of generation of code ('Code Injection') in the settings feature in Devolutions Pow…
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-15205] The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplie…
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user c…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72850] Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to…
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72839] filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is ena…
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.