Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-46670] YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection i…
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72748] AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json…
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achiev…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-58115] A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions <…
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attac…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-18972] An authenticated attacker can spoof another GUI user's identity by sending their request with the cu…
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
M Crítico vulnerabilidad
11/08/2026
Inyección de comandos OS en wg-easy 15.3.0 permite ejecución como root
Una vulnerabilidad crítica en wg-easy 15.3.0 permite a usuarios con permiso clients.create ejecutar comandos arbitrarios como root mediante inyección de directivas WireGuard malformadas en el campo de nombre del cliente. El software no sanitiza caracteres de salto de línea en la configuración, exponiendo servidores VPN corporativos en LATAM que utilicen esta herramienta de gestión. El acceso requerido es limitado, pero el impacto potencial es total compromiso del sistema.
M Crítico vulnerabilidad
11/08/2026
Inyección SQL crítica en e107 2.4.0 permite acceso no autenticado a bases de datos
Una vulnerabilidad de inyección SQL en e107 2.4.0 permite a atacantes no autenticados ejecutar comandos SQL arbitrarios a través del parámetro de ID de noticia, comprometiendo completamente la integridad de la base de datos. Los atacantes pueden leer, modificar o eliminar todos los contenidos, incluidas credenciales de administrador. Esta falla afecta directamente a portales de contenidos, sitios informativos y plataformas comunitarias desplegadas en LATAM sin parches aplicados.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72550] An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated re…
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW COLUMNS query via a bare PDO::query() call, enabling stacked statement injection. An unauthenticated attacker can read, modify, or delete the entire database.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-58231] SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and s…
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-10579] A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged …
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19516] A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re…
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-13716] Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authent…
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19425] Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability…
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-34265] SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors i…
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-44758] SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to subm…
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability …
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72911] ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, …
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted globals including frappe.utils, allowing an authenticated user with a common operational role to inje…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-18948] A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored i…
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the regis…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-14450] A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the…
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized access and escalate privileges. The concrete consequences include the ability to mint …
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72886] Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.c…
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin host-schedule gate only in the alternative branch, allowing a member with access to one application to attach its applicationId to a dokploy-server sc…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72901] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an a…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create and volumeBackup.runManually is interpolated without quoting in packages/server/src/utils/volume-backups/backup.ts and executed through child_process…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72902] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an a…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server because registry.testRegistry and registry.testRegistryById in apps/dokploy/server/api/routers/registry.ts interpolate the password field into an execAsyncRemote shell command instead of using safeDockerLoginCo…