Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 4193 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81048] Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elemen…
Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution
M Alto vulnerabilidad
10/09/2026
[CVE-2026-79987] A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission ca…
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-4130] There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulner…
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88924] A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownersh…
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an ar…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84816] Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WPCS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84819] Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WPAdverts
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81799] Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 version…
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81803] Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Subscriber Remote Code Execution (RCE) in RepairBuddy
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81804] Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versi…
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81795] Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81789] Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6…
Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88889] Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that…
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySour…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88890] OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter bui…
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analyti…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88891] OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing …
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88885] Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when process…
Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters through malicious dependency names to execute arbitrary commands as the Renovate user during Go module major version updates with postUpdateOptions gomodUpdateImpo…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88888] Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processin…
Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names to execute arbitrary commands as the Renovate user in binarySource=docker mode.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88877] Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kuberne…
Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88880] Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagi…
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88881] Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HT…
Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL is not validated against the host originally contacted, a malicious or compromis…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88869] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execu…