Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1797
Esta semana
RSS
M Alto vulnerabilidad
09/08/2026
Vulnerabilidad alta de inyección de comandos en Tenda CH22 1.0.0.1
Se identificó una vulnerabilidad de inyección de comandos (CVE-2026-19346, CVSS 8.8) en el router Tenda CH22versión 1.0.0.1, específicamente en la función formCertListInfo del endpoint /goform/CertListInfo. Un atacante remoto puede manipular el parámetro Name para ejecutar comandos arbitrarios sin autenticación. Esta vulnerabilidad está públicamente divulgada y es activamente explotada en ataques.
M Alto vulnerabilidad
09/08/2026
Inyección SQL alta en Task Management System 1.0 permite acceso remoto a bases de datos
Se ha identificado una vulnerabilidad de inyección SQL en code-projects Task Management System 1.0 a través del parámetro task_id en el archivo /user/comment_count_user.php. Esta falla permite a atacantes remotos comprometer la integridad y confidencialidad de datos, siendo especialmente alta para empresas en LATAM que gestionan información sensible de proyectos. El exploit ha sido divulgado públicamente, aumentando el riesgo inmediato de explotación.
M Alto vulnerabilidad
09/08/2026
Inyección SQL alta en Task Management System 1.0 de code-projects
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-19343, CVSS 7.3) en code-projects Task Management System 1.0 a través del archivo /admin/AdminLogin.php. Un atacante remoto puede manipular los parámetros de email/password para ejecutar comandos SQL arbitrarios y comprometer la integridad de bases de datos. El exploit está disponible públicamente, lo que aumenta significativamente el riesgo para empresas mexicanas y latinoamericanas que utilizan este sistema.
M Alto vulnerabilidad
08/08/2026
Inyección de comandos alta en INQUIRELAB mcp-bridge-api (CVE-2026-19263)
Se identificó una vulnerabilidad de inyección de comandos en el componente Servers Endpoint del archivo mcp-bridge.js de INQUIRELAB mcp-bridge-api. Un atacante remoto podría manipular los parámetros command/args para ejecutar comandos arbitrarios en servidores afectados. Esta vulnerabilidad impacta directamente sistemas de integración de APIs en infraestructuras empresariales de México y Latinoamérica que utilizan esta librería en versiones anteriores a b30a82aa1d1d1139e0de846c41c8aadee6e06114.
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta en Kakoune permite ejecución remota de comandos vía archivos de respaldo
Kakoune, editor de código utilizado por desarrolladores en LATAM, contiene una vulnerabilidad de ejecución arbitraria en versiones anteriores a 2026.05.21. La función autorestore.kak, habilitada por defecto, puede ser explotada mediante archivos de respaldo maliciosos para ejecutar comandos de shell sin intervención del usuario. Afecta principalmente a equipos de desarrollo y DevOps que utilizan este editor en entornos de producción.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-19231] A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vu…
A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-19211] A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown functio…
A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/08/2026
SQL Injection alta en SourceCodester Photo Share Website 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester Photo Share Website 1.0 mediante la manipulación del parámetro email en /social/ajax.php?action=login. El exploit es de acceso público y permite a atacantes remotos comprometer bases de datos de aplicaciones web en empresas mexicanas y latinoamericanas que utilizan esta plataforma. Con CVSS 7.3, representa un riesgo considerable para la confidencialidad e integridad de datos de usuarios.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19062] A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. …
A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument zuname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Ther…
M Alto vulnerabilidad
06/08/2026
Inyección SQL alta en SourceCodester Computer Repair Shop Management System 1.0
Se detectó una vulnerabilidad de inyección SQL en SourceCodester Computer Repair Shop Management System versión 1.0, específicamente en el archivo /classes/Master.php?f=delete_product mediante manipulación del parámetro ID. El exploit ha sido divulgado públicamente, permitiendo ataques remotos sin autenticación. Afecta principalmente a talleres de reparación y empresas de servicios técnicos en México y LATAM que utilicen este sistema para gestionar inventario de productos.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18970] A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617.…
A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclos…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71320] Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an …
Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fixed in 3.21.10 and 4.5.1.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18958] A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79…
A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnerability is an unknown functionality of the file loginCheckTest.php of the component Login. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit is n…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-20272] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of spec…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18902] A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function es…
A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18859] A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of th…
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18854] A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. T…
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18814] A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of th…
A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18813] A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /a…
A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18811] A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the f…
A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.