Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Nsa" — 142 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105385] A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transaction_details.php. Executing a manipulation of the argument transaction_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utiliz…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105383] A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This impacts an unknown function of the file php/controller.php. Such manipulation of the argument transaction_idS leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling relea…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104970] Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint …
Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or advisory lock. Two concurrent unauthenticated requests with different email addresses …
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105218] gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go…
gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad XSS almacenado alta en plugin WP Mail Catcher para WordPress (CVE-2026-93889)
El plugin WP Mail Catcher para WordPress es vulnerable a inyección de scripts maliciosos almacenados (Stored XSS) a través de mensajes de error de PHPMailer en versiones hasta 2.1.12. Atacantes no autenticados pueden inyectar código JavaScript que se ejecuta cuando usuarios acceden a páginas comprometidas, poniendo en riesgo datos sensibles y sesiones administrativas. Afecta especialmente a sitios empresariales en LATAM que utilizan este plugin para gestionar logs de correo.
M Alto vulnerabilidad
Hace 6 días
Inyección SQL alta en Smart Manager para WooCommerce afecta tiendas online
El plugin Smart Manager para WordPress es vulnerable a inyección SQL a través del parámetro 'access_privileges' en versiones hasta 8.97.0. Atacantes autenticados pueden ejecutar consultas maliciosas y comprometer datos de inventario, clientes y transacciones en tiendas de comercio electrónico. El riesgo es alto en plataformas multitienda comunes en México y Latinoamérica que usan este plugin para gestión masiva de productos.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-82039] UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBu…
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arb…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104435] Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 tra…
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104437] Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verific…
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104431] Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to s…
Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresp…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104422] The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalida…
The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the re…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104423] Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows un…
Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-54049] Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and vers…
Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversa…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-55083] DHIS2 is a flexible information system for data capture, management, validation, analytics and visua…
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102101] Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserializ…
Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102094] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does …
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentia…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103398] OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifes…
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-97196] Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP al…
Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-68068] The "screenID" parameter in the electronic transaction queue viewer feature within the manual transa…
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102827] simple-git, an interface for running git commands in any node.js application, enables applications t…
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --e…