Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 7288 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97363] The WebSocket Application Programming Interface lacks restrictions on the number of authentication r…
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-82042] UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers…
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtai…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-82039] UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBu…
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arb…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-104019] OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution …
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in …
M Crítico vulnerabilidad
02/10/2026
[CVE-2023-54405] H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an un…
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token pa…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-67989] crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular…
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
M Alto vulnerabilidad
02/10/2026
[CVE-2026-51907] In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vul…
In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-51916] TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_use…
TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-101104] The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows auth…
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104637] A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remo…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-93875] The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friend…
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload …
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-19652] The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, an…
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowe…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-104610] A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impact…
A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-104611] A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /…
A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de carga de archivos sin restricción en YesWiki anterior a 4.6.7
YesWiki versiones anteriores a 4.6.7 presentan una vulnerabilidad de carga de archivos no restringida que permite a administradores autenticados ejecutar código PHP malicioso en el servidor mediante la importación de CSV en Bazar. Un atacante puede importar un archivo CSV con referencias a URLs PHP remotas que se guardan sin validación de extensión y se ejecutan como código del lado del servidor, comprometiendo la integridad del sitio web y los datos alojados.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de autorización en YesWiki anterior a 4.6.7 expone archivos confidenciales
YesWiki versiones anteriores a 4.6.7 contienen una falla de autorización en el manejador de descargas que permite a atacantes no autenticados eludir controles de acceso (ACLs) y descargar archivos adjuntos de páginas restringidas. Esta vulnerabilidad afecta principalmente a organizaciones en LATAM que utilizan wikis internas para gestión documental, exponiendo información sensible como reportes, datos financieros y documentación confidencial sin requerir credenciales válidas.
M Alto vulnerabilidad
02/10/2026
Inyección SQL alta en onetwothreeneth HospitalManagementSystem permite acceso remoto no autorizado
Se identificó una vulnerabilidad de inyección SQL en onetwothreeneth HospitalManagementSystem (hasta versión 9ef91ed6007314b6473110ed699dff76d158f61d) en el archivo edit_accounts.php. Un atacante remoto puede manipular los parámetros user_id, patient_id, physician_id, discounts_id o services_id para ejecutar comandos SQL arbitrarios, comprometiendo bases de datos de pacientes, registros clínicos y datos sensibles. La explotación es posible sin autenticación previa y el exploit ya está disponible públicamente.
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de bypass de autorización en YesWiki anterior a 4.6.7
YesWiki versiones anteriores a 4.6.7 contiene un defecto de autorización en ApiService::isAuthorized() que permite a atacantes no autenticados invocar rutas API administrativas cuando el modo API público está habilitado. Los atacantes pueden modificar configuraciones, acceder y eliminar archivos de respaldo mediante endpoints como api/ci/update_config y api/archives, comprometiendo la integridad y disponibilidad de wikis empresariales en LATAM.
M Alto vulnerabilidad
02/10/2026
Inyección SQL ciega en YesWiki anterior a 4.6.7 permite lectura de datos arbitrarios
YesWiki versiones anteriores a 4.6.7 contiene una vulnerabilidad de inyección SQL ciega en la acción {{newtextsearch}} que permite a atacantes anónimos explotar opciones de listas Bazar sin escapado en la consulta SQL. Los atacantes pueden manipular opciones en listas editables anónimamente y usar solicitudes de búsqueda como oráculo booleano para extraer datos sensibles de la base de datos, incluyendo credenciales e información confidencial. Afecta principalmente a wikis colaborativas en LATAM con acceso público o semi-público.
M Alto vulnerabilidad
02/10/2026
Inyección SQL alta en YesWiki anterior a 4.6.7 afecta plataformas colaborativas
YesWiki versiones anteriores a 4.6.7 contienen una vulnerabilidad de inyección SQL en la acción Bazar nuagetag que permite a atacantes con acceso de escritura (sin autenticación en instalaciones por defecto) extraer hashes de contraseñas y datos arbitrarios de bases de datos. Esta exposición es alta en entornos educativos y colaborativos frecuentes en LATAM donde YesWiki se utiliza para wikis organizacionales sin autenticación requerida.