Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Gnu" — 55 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-108157] Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that all…
Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the vi…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-95209] An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of …
An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS).
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-95184] Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certif…
Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of Service (DoS).
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-95210] Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates cont…
Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105920] A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e96643…
A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The impacted element is an unknown function of the file student_signup.php of the component Student Registration Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product use…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105471] A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757…
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105639] Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logge…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer u…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104970] Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint …
Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or advisory lock. Two concurrent unauthenticated requests with different email addresses …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105231] A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72…
A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is an unknown function of the file admin/signup.php of the component Admin Registration. The manipulation of the argument email/username/location results in sql injection. It is possible to launch the attack remotely. The exp…
M Alto vulnerabilidad
Hace 4 días
Inyección SQL alta en sistema de gestión de residuos food-waste-management-system
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-105232, CVSS 7.3) en el archivo deliverysignup.php del componente de página de registro del sistema food-waste-management-system. Un atacante remoto puede manipular los parámetros username, email o location para ejecutar comandos SQL arbitrarios. Esta vulnerabilidad afecta sistemas de gestión de residuos implementados en restaurantes, cadenas de comida rápida y empresas de distribución en LATAM que utilicen esta plataforma.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105229] A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument email/name/gender can lead to sql injection. The attack may be performed from remote. The ex…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105170] A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the p…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-55160] Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-S…
Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS IMDS 169.254.169.254). When self-service signup is enabled (Setting::UserSignup),…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-100310] GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACT…
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-14281] The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo…
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/` and the absence of a key allowlist in the `finish_registration_logic` function, which…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84975] PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, …
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values with string functions that recalculate their length and truncate an embedded NUL byte. With server verification enabled through --tls-verify-server for the PJSIP TLS/SIPS t…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81180] SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users …
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-52727] lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch…
lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-89036] Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users w…
Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the providerRootDirectory parameter used to construct GNU tar commands. The application uses escapeshellcmd instead of escapeshellarg and fails to quote the parameter, allowing TAB character…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90856] A security vulnerability has been detected in SourceCodester College Notes Gallery Management System…
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.