Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 min
Buscando: "Ni" — 4220 resultados ✕ Limpiar búsqueda
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1783
Esta semana
RSS
M Alto vulnerabilidad
12/08/2026
[CVE-2026-71473] A flaw was found in the `search-v2-operator` component. A user with specific administrative permissi…
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially com…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73493] Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.2…
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denia…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19003] A data source definition containing an over-length file path setting may cause the MongoDB BI Connec…
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when a user opens the setup dialog for such a data source and initiates a file or fol…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-71469] A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests …
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-71471] A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub clust…
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attac…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17485] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain s…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-66898] A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during back…
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing pa…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13367] IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in th…
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13622] A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live …
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc//root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions ca…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16033] A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unco…
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a cr…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73329] CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privi…
CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can submit a malicious HTML payload as a draft title through the drafts creation endpoint, which is persisted to the databas…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73331] CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated at…
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing SQL syntax that the database backend evaluates as part of an inadequately parameterized query. Attackers can supply malicious slug payloads using boolean- or union-style blind SQL injection techniques to extra…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73332] CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin tha…
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in vic…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73326] CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privile…
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to al…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72809] SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the …
SiYuan versions

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72795] SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBloc…
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72793] SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf…
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate …
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72794] siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf …
siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access.
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-63298] An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration …
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execut…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13361] IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.