Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3515 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Alto vulnerabilidad
29/08/2026
[CVE-2026-76548] The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end fil…
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16947] The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a …
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success respon…
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16259] The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified th…
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password,…
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta de intercepción de tráfico en BOSH Director vCenter CPI (CVE-2026-41012)
Una vulnerabilidad de intercepción de tráfico en BOSH Director vCenter CPI permite a atacantes posicionados entre el Director y vCenter suplantar la API REST de vCenter y capturar credenciales de administrador mediante autenticación HTTP Basic. Un atacante con capacidad de interceptar tráfico puede comprometer completamente la infraestructura de virtualización. En LATAM, esto afecta altas centros de datos y plataformas de IaaS que dependen de vCenter para gestión de máquinas virtuales.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad en mongosqld: certificados de cliente no validados correctamente
mongosqld no valida correctamente los certificados de cliente durante el handshake TLS cuando está configurado con una autoridad certificadora. Esto permite que clientes sin certificado establezcan sesiones, comprometiendo la autenticación en entornos que dependen exclusivamente de certificados para identificar usuarios. Empresas en LATAM que utilizan MongoDB BI Connector con autenticación basada en certificados están expuestas a acceso no autorizado.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en MongoDB Connector for BI ODBC: desbordamiento de búfer por inyección SQL
Un atacante puede enviar consultas SQL malformadas a través del controlador ODBC de MongoDB Connector for BI, especificando nombres de cursor que exceden los límites internos del búfer. Esto provoca sobrescritura de memoria adyacente, potencialmente causando denial of service (DoS) o ejecución de código arbitrario en aplicaciones que integren este conector. Afecta directamente a plataformas de análisis y Business Intelligence que dependan de este driver en entornos LATAM.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad en multer 2.2.0: descriptor de archivo no cerrado en cargas abortadas
multer, middleware de Node.js para procesar multipart/form-data, presenta una vulnerabilidad en la versión 2.2.0 donde las cargas abortadas o truncadas no cierran correctamente los descriptores de archivo, dejándolos abiertos en el sistema. Esto permite a atacantes remotos consumir recursos del servidor y potencialmente acceder a información sensible. El riesgo es alta en aplicaciones web que manejan uploads de usuarios sin autenticación robusta.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-19295] IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operatin…
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing …
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-18527] IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow…
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82288] Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v…
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82280] Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users …
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82284] Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, D…
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82266] Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t…
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82269] Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API …
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55634] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55484] ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking …
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a question mark and then performs the unchecked p[0] access without checking whether the resulting path is empty. An unauthenticated client can send a malformed…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54745] Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. …
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its o…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54755] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckVa…
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en gitoxide anterior a 0.52.1 permite inyección de metadatos de submódulos
gitoxide versiones anteriores a 0.52.1 presenta una vulnerabilidad que permite a atacantes seguir enlaces simbólicos en el archivo .gitmodules del árbol de trabajo, facilitando la inyección de bytes maliciosos en metadatos de submódulos. Un repositorio malicioso puede redirigir la lectura de configuración hacia archivos externos arbitrarios, exponiendo información controlada por el atacante en nombres, rutas y URLs de submódulos. Afecta principalmente a equipos de desarrollo que utilizan gitoxide para control de versiones en México y Latinoamérica.