Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 4143 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
13/09/2026
[CVE-2026-15891] The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the …
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents. The code then derefere…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-85129] The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one…
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's …
M Alto vulnerabilidad
13/09/2026
[CVE-2026-88793] The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one…
The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an adminis…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90593] A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw:…
A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-37008] CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstrac…
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox …
M Alto vulnerabilidad
13/09/2026
[CVE-2026-74933] The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of …
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.
M Crítico vulnerabilidad
13/09/2026
[CVE-2026-81648] The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check…
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/09/2026
[CVE-2026-36453] Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be…
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90579] A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the func…
A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early th…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90566] A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5…
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90524] A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a…
A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a ro…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90526] A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0.…
A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90522] A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b…
A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with …
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90783] MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superi…
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de desbordamiento de búfer en SIPp 3.7.7 y versiones anteriores
SIPp versiones hasta 3.7.7 contiene un desbordamiento de búfer en la función get_header() que permite a atacantes no autenticados enviar mensajes SIP con encabezados superiores a 20,490 bytes para causar crasheo del proceso. Esta vulnerabilidad afecta servidores VoIP y sistemas de prueba de telefonía en infraestructuras empresariales de LATAM. El impacto incluye negación de servicio en infraestructuras de comunicaciones altas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad de denegación de servicio en Nodemailer 9.1.0 a 10.0.4 (CVE-2026-90776)
Nodemailer versiones 9.1.0 a 10.0.4 contienen una vulnerabilidad de complejidad cuadrática en el parser de direcciones que procesa comentarios RFC 5322. Atacantes pueden enviar encabezados de correo malformados para consumir CPU excesiva y bloquear el event loop de Node.js durante varios segundos, generando negación de servicio. Afecta especialmente a plataformas de notificaciones y sistemas de correo transaccional en LATAM que procesan volúmenes altos de mensajes.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta en ESPnet permite ejecución arbitraria de código en modelos entrenados
ESPnet anterior a versión 202609 deserializa puntos de control de modelos preentrenados usando torch.load sin validación (weights_only=False), permitiendo ejecución de código arbitrario desde archivos maliciosos. Atacantes pueden crear archivos de punto de control comprometidos que ejecutan código durante la carga en procesos de inicialización o ajuste fino, comprometiendo sistemas de procesamiento de voz e IA en empresas LATAM que dependan de esta librería.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de desbordamiento de búfer en SIPp 3.7.7 y anteriores
SIPp versiones hasta 3.7.7 contiene un desbordamiento de búfer en la función get_peer_tag() al procesar encabezados SIP con parámetros de etiqueta superiores a 2048 bytes. Atacantes no autenticados pueden enviar mensajes SIP manipulados para causar el bloqueo de procesos en servidores de comunicaciones VoIP y telefonía empresarial. Este riesgo afecta infraestructuras de telefonía en la nube y sistemas PBX que implementen SIPp.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de inyección SQL en SourceCodester School Registration and Fee System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System 1.0 que afecta el archivo /bilal/normal/delete_stud.php. Un atacante remoto puede manipular el parámetro selector[] para ejecutar comandos SQL arbitrarios y comprometer bases de datos de instituciones educativas. La vulnerabilidad tiene CVSS 7.3 y exploits públicos disponibles, representando riesgo inmediato para sistemas de registro y gestión de matrículas en centros educativos de LATAM.
M Alto vulnerabilidad
13/09/2026
Inyección SQL alta en SourceCodester School Registration and Fee System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System 1.0 en el archivo /bilal/normal/pay_report.php, permitiendo manipulación del parámetro 'period' para ejecutar comandos SQL arbitrarios. El exploit es público y explotable remotamente, afectando directamente instituciones educativas en México y LATAM que utilizan este sistema para gestión de matrículas y cobros. Con CVSS 7.3, requiere acción inmediata en entornos de producción.