Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Ni" — 2091 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90846] A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknow…
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-90847] A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown functio…
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91751] Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entrie…
Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate arbitrary files and directories on the filesystem.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90843] A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b89…
A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Th…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90844] A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affe…
A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90841] A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by thi…
A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be u…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90840] A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the func…
A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-91145] Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, al…
Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-12944] IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root…
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90819] A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function Ba…
A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting. The attack can be initiated remotely. Upgrading …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-84553] A resource exhaustion issue was addressed with improved input validation. This issue is fixed in mac…
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-43692] A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Gold…
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote user may cause an unexpected app termination or arbitrary code execution.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-28960] A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10…
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-19624] A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection proper…
A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security assoc…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90809] A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function Ex…
A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection. It is possible to launch the attack remotely. The name of the patch is af582246f141311d574551b7571a517bcc3df750. It is best practice to apply a pat…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-89023] ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vuln…
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, m…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-86830] Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity C…
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has b…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82035] PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font…
PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output directory without stripping path separators or dot-dot sequences. Attackers can supply a crafted PDF, EPUB, XPS, or FB2 file…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90945] Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be over…
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90946] DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenti…
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.