Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
14,926
Total alertas
3375
Críticas
11163
Altas
8
Ransomware
888
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-81491] A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_…
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has no…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-81421] A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element i…
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem earl…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47851] Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in t…
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47852] A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malici…
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81203] A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affect…
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-47665] Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Pe…
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any tea…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-47666] Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Pe…
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected into the page as HTML without sanitization. Because the backend accepts an arbitrary font-family string and the frontend writes the resulting style throu…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77611] SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authent…
SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object outside that scope by calling PutObjectAcl on the key it is allowed to access. The handler authorizes the request against the requested nested key but then writes the updated entry back to the bucket …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81202] A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function creat…
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77317] SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, t…
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose name merely begins with the same characters. A user granted access to /tenants/alice therefore also matches /tenants/alic…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77368] SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resu…
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upload session to write content to filer paths their own token forbids. The HEAD, PATCH, and DELETE verbs that act on an existing session by its id never ve…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-61617] Wings is the server control plane for the Pterodactyl game-server management panel. In versions up t…
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down every server on it. Wings checks available space only once, as a boolean, when the …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-61792] Weblate is a web-based continuous localization platform used to manage software translations. In ver…
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths without adequately confining them to the repository. This is an incomplete fix for CVE-2026-34242, whose original patch fai…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-55228] Weblate is a web-based continuous localization platform used to manage software translations. In ver…
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not au…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-79938] Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnera…
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77652] A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer…
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB, 256); When handling a WPG_COLORMAP record, the parser reads a start index (i16) and number of colors (iNum16) from the file and reads palette data with: bRet &= (iNum16…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-74770] Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special El…
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-68861] Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special El…
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-68863] Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerabil…
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-46369] Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus…
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transaction::is_valid_at, allowing a remote attacker to replay the same signed transaction during a blocks_per_batch minus one block window and cause the sender …