Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3515 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18672] In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied s…
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81737] The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by u…
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19723] The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properl…
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPr…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19116] The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from b…
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84700] PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the cl…
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84696] Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique comm…
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84699] Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local ac…
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84350] Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leverag…
Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-75604] Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and…
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-73770] An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could …
An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-73710] Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated …
Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-72649] Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead…
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and de…
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad alta en yast2-samba-client permite ejecución de comandos como root
Una falla de neutralización de caracteres especiales en yast2-samba-client (versiones hasta 5.0.4) permite a un atacante con control sobre un controlador de dominio Active Directory malicioso ejecutar comandos arbitrarios con privilegios root en máquinas siendo unidas al dominio. Afecta directamente servidores Linux en entornos corporativos que integran Active Directory, común en infraestructuras híbridas de LATAM con dominios Windows centralizados.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-75921] The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widge…
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the upload_template_kit function. This is due to incorrect authorization on the upload_template_kit() AJAX handler, which requires only upload_files capability instea…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82392] pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package n…
pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82908] A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is th…
A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacte…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81889] elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1…
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects fsock_get_contents(), which connects to $arr['host'] and performs a second DNS resol…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81891] elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1…
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap entries that map them to text/x-php are not appli…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81892] EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 an…
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security …
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-79748] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication is requi…