Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 5251 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en Shelf permite inyección SSRF en importación de activos
Shelf, plataforma de gestión de inventarios físicos, contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) en versiones anteriores a 1.20.3. Usuarios autenticados con permisos de importación pueden eludir validaciones de URL en la función de importación CSV para ejecutar peticiones HTTP a servidores controlados por atacantes. Afecta principalmente a empresas LATAM que gestionan activos tecnológicos y de infraestructura a través de esta plataforma.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad en Melange y Apko permite instalar paquetes APK maliciosos sin validación
Melange versiones anteriores a 0.50.4 y Apko anteriores a 1.2.9 no verifican la integridad de los archivos de datos en paquetes APK durante la instalación, solo validan metadatos. Un atacante que controle un espejo, envenenene un caché o realice ataques MITM puede distribuir paquetes comprometidos que se instalarán sin detección. Afecta infraestructuras que utilizan estos gestores de compilación en entornos Linux containerizados.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de control de acceso en NL Portal Backend Libraries permite acceso no autorizado a tareas
El paquete `nl.nl-portal:taak` (versiones 1.5.0 a 3.0.0) no valida correctamente la propiedad de tareas en la mutación GraphQL `submitTaakV2`, permitiendo a usuarios autenticados leer formularios de otros usuarios si conocen o adivinan su ID de tarea. Esta vulnerabilidad afecta sistemas de gobierno digital en portales de atención ciudadana que procesan información sensible de residentes, clientes y proveedores.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-53952] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installatio…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-54135] AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions pr…
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and direct…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-79393] A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in th…
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-79395] An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routin…
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62112] Editor SQL Injection in Amelia <= 2.4.9 versions.
Editor SQL Injection in Amelia
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62102] Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
Subscriber Privilege Escalation in Gato GraphQL
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-62103] Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Unauthenticated PHP Object Injection in Everest Forms
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-62105] Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62106] Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
Subscriber Privilege Escalation in SMS Alert Order Notifications
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62107] Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
Unauthenticated PHP Object Injection in Masteriyo - LMS
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62109] Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
Editor SQL Injection in Sky Addons for Elementor
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-54072] Authorizer is an open-source, self-hostable authentication and authorization server. Prior to versio…
Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-suppl…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62089] Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse…
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89099] A race condition in the document value layer of MongoDB Server can allow concurrent server threads t…
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of p…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78807] An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper netwo…
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-72709] SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpo…
SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without any server-side permission check via autoriser(). Attackers can obtain a valid nonce, compute it for any action as the anonymous user, and invoke the editer_au…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-72710] SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where t…
SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject attacker-controlled rows into the spip_jobs table. Attackers can supply arg=job/0 with crafted fonction and args values, which are later unserialized and execute…