Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 2109 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47494] NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a f…
NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a format string issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103229] A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e…
A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be u…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103230] A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcf…
A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103231] A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcf…
A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The proj…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100268] In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other proj…
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100255] In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possib…
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103398] OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifes…
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103270] LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without a…
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96827] Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.
Administrator SQL Injection in Admin Notices Manager
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96828] Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
Administrator SQL Injection in Category Discount Woocommerce
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96345] Administrator SQL Injection in Estatik <= 4.3.5 versions.
Administrator SQL Injection in Estatik
M Alto vulnerabilidad
30/09/2026
[CVE-2026-93651] Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce
M Alto vulnerabilidad
30/09/2026
[CVE-2026-62085] Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
Administrator SQL Injection in WP Activity Log
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102385] Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-88920] An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote…
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad alta en CRI-O permite escape de contenedores mediante corrupción de metadatos
Una falla en la persistencia del estado sandbox de CRI-O permite que metadatos manipulados sobrescriban la información de control interno, que luego se carga como confiable tras un reinicio. Esto habilita que contenedores expongyan recursos del host, facilitando escapes. Afecta plataformas Kubernetes en producción en LATAM que dependan de CRI-O como runtime de contenedores.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-85532] Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. T…
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes. Users are recommended to upgrade to versions 4.0.2…
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad alta en CODESYS Gateway Client permite denegación de servicio remota
El cliente CODESYS Gateway asigna memoria basándose en campos de tamaño en respuestas de gateway sin límites superiores, permitiendo a atacantes remotos no autenticados consumir recursos excesivos mediante un gateway malicioso. Esta vulnerabilidad afecta sistemas de automatización industrial (SCADA/ICS) en manufactura, servicios públicos y plantas de México y Latinoamérica, resultando en pérdida total de disponibilidad de los sistemas afectados.
M Crítico vulnerabilidad
30/09/2026
Omisión de validación en Apache MINA SSHD permite eludir autenticación LDAP
Apache MINA SSHD versiones 1.2.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5 contienen una falla en LdapPasswordAuthenticator que permite bypass de autenticación. Afecta servidores SSH en Java que integren LDAP para validación de credenciales, comprometiendo el acceso a sistemas críticos de infraestructura en organizaciones latinoamericanas.
M Crítico vulnerabilidad
30/09/2026
Omisión de autenticación en Apache MINA SSHD 2.0.0 a 3.0.0-M5 (CVE-2026-77185)
Apache MINA SSHD, librería Java para implementar servidores SSH, contiene una vulnerabilidad crítica (CVSS 9.1) que permite eludir la autenticación en configuraciones específicas de autenticación asincrónica. Afecta principalmente a servidores SSH personalizados en entornos de infraestructura crítica, plataformas de acceso remoto y soluciones de integración en LATAM. La explotación podría comprometer la integridad de sistemas de gestión de infraestructura, bases de datos y servidores de aplicaciones.