Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35080] The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local f…
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35081] The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processe…
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35082] The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files…
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35083] A remote attacker with user privileges can exploit a stack buffer overflow to gain full system acces…
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
M Crítico vulnerabilidad
03/06/2026
[CVE-2026-35075] An unauthenticated remote attacker can recover a default, hard coded password from a firmware image …
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35076] The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local fi…
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35077] The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local …
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35078] The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local file…
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
A Alto vulnerabilidad
03/06/2026
[CVE-2025-14774] Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
M Alto vulnerabilidad
03/06/2026
[CVE-2025-15655] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0.
M Alto vulnerabilidad
03/06/2026
[CVE-2025-15656] Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalati…
Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-41032] It is possible for an unauthenticated adjacent attacker to download log files of the controller, whi…
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
A Crítico vulnerabilidad
03/06/2026
[CVE-2026-47065] ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Pro…
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which perform…
A Alto vulnerabilidad
03/06/2026
[CVE-2025-14772] Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affect…
Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
A Alto vulnerabilidad
03/06/2026
[CVE-2025-14773] Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Crítico vulnerabilidad
03/06/2026
[CVE-2025-14771] Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue aff…
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
L Alto vulnerabilidad
03/06/2026
[CVE-2026-4035] A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment v…
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's env…
M Alto vulnerabilidad
03/06/2026
[CVE-2025-15654] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-50031] ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intell…
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors comma…
M Alto vulnerabilidad
03/06/2026
[CVE-2026-10704] A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulne…
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.