Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Ui" — 3508 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
04/09/2026
[CVE-2026-80113] PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics …
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address parameter in an exposed IOCTL handler. Attackers can obtain a device handle and suppl…
M Alto vulnerabilidad
04/09/2026
[CVE-2021-44320] Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (D…
Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19306] IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from …
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file content…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-19274] IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator coul…
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlle…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19283] IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator coul…
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19298] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85607] Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (mess…
Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures require authentication, they query the database by caller-supplied conversation or message ID without verifying…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad de omisión de autorización en snipe-it anterior a 8.6.3 afecta gestión de usuarios
snipe-it versiones anteriores a 8.6.3 contienen una vulnerabilidad de omisión de autorización en la funcionalidad de eliminación masiva que permite a usuarios restringidos eliminar de forma reversible usuarios fuera de su alcance autorizado. Los atacantes pueden incluir IDs de usuario no autorizados en solicitudes de eliminación masiva para eludir restricciones a nivel de instancia y modificar o desactivar cuentas que no deberían poder acceder. Esta vulnerabilidad afecta directamente a empresas LATAM que utilizan snipe-it para gestión de inventario de TI.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad alta en OpenPanel anteriores a 2.3.0 permite ejecución de código remoto
OpenPanel versiones anteriores a 2.3.0 contiene una falla en la validación de expresiones de fórmulas en gráficos que permite a miembros autenticados del proyecto con acceso de lectura ejecutar código arbitrario. Los atacantes pueden recuperar el constructor nativo de JavaScript a través de objetos matriz de mathjs, cargar módulos de Node.js y ejecutar comandos del sistema operativo con privilegios del proceso API, comprometiendo completamente la infraestructura.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad XPS almacenado en Grav Shortcode Core anterior a 6.2.5
Grav Shortcode Core versiones anteriores a 6.2.5 contiene vulnerabilidades de cross-site scripting (XSS) almacenado en los parámetros de etiqueta [lorem] y resumen [details], que se renderizan sin validación. Atacantes con acceso de edición pueden inyectar código HTML y JavaScript arbitrario que se ejecuta en navegadores de visitantes, incluidos administradores. Afecta sitios Grav en producción que permiten edición de contenido a múltiples usuarios.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad de denegación de servicio en SiYuan anterior a v3.8.2
SiYuan versiones anteriores a la 3.8.2 contienen una vulnerabilidad de denegación de servicio (DoS) en el endpoint /api/system/uiproc sin autenticación. Un atacante puede enviar solicitudes repetidas con identificadores de proceso controlados para agotar la memoria y degradar la disponibilidad del servicio. Esta vulnerabilidad afecta a empresas en LATAM que utilizan SiYuan como gestor de notas o información sensible sin actualizar.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad en Fastify anterior a v5.12.2 por validación incompleta de encabezados HTTP
Fastify versiones anteriores a 5.12.2 presentan una validación incompleta de encabezados HTTP case-insensitive en esquemas de rutas. La transformación de minúsculas no se aplica correctamente en dependencias JSON Schema Draft 7, permitiendo que propiedades no normalizadas en el esquema causen comportamiento inesperado o bypass de validaciones. Esto afecta a aplicaciones Node.js en producción que dependen de validación estricta de encabezados para autenticación, autorización o filtrado de solicitudes.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-82923] The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or n…
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads di…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-81665] A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembl…
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85379] A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf4…
A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterModel::searchChapter of the file App/Home/Controller/ChapterController.class.php of the component Query Builder. The manipulation of the argument content results in sql injection. The attack can be launched remotely. The exploit ha…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85451] MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSle…
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85452] MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeG…
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64197] There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied…
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64198] There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied …
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64199] There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied …
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.