Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 940 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103098] Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent…
Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103096] API key is hardcoded and retrievable from the application package. Since Android applications can be…
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-86345] A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a…
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a cl…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-103765] Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata s…
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server …
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103766] ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated u…
ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user credentials and emails or modify and delete arbitrary records.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103761] Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in Transfer…
Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-86344] A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operati…
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing d…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-56660] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to b…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-53953] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-53964] Document Merge Service is a document template merge service providing an API to manage templates and…
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerab…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-54049] Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and vers…
Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversa…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103484] IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, whi…
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-102628] The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=tru…
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-102667] Joyland AI app allows an attacker with shared network access to inject JavaScript into content loade…
Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, mi…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-55083] DHIS2 is a flexible information system for data capture, management, validation, analytics and visua…
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-55232] Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor…
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated adm…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-104057] Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurr…
Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigge…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-104059] Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blue…
Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a m…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97662] An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before versi…
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation. To remediate this issue, users should upgrade to version 0.2.0.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-68495] The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validate…
The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and CBORParser._decodeChunkedName() delegates to the value-oriented _finishChunkedText() rou…