Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
23/08/2026
[CVE-2026-78143] A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. A…
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
23/08/2026
[CVE-2026-78141] A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of th…
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
23/08/2026
Inyección de comandos alta en Tenda CH22 1.0.0.1 permite acceso remoto no autorizado
Se ha identificado una vulnerabilidad de inyección de comandos en el router Tenda CH22 versión 1.0.0.1 a través de la función formeditFileName del archivo /goform/editFileName. Un atacante remoto puede ejecutar comandos arbitrarios manipulando el parámetro editNameMit sin autenticación previa. El exploit ha sido publicado públicamente, incrementando el riesgo de explotación masiva en infraestructuras de LATAM que utilizan este modelo de router.
M Alto vulnerabilidad
22/08/2026
Inyección de comandos en TRENDnet TEW-821DAP 2.2.01b05 permite ejecución remota
Se identificó una vulnerabilidad de inyección de comandos en el dispositivo TRENDnet TEW-821DAP versión 2.2.01b05 a través del parámetro filename en /cgi-bin/upload.cgi. Un atacante remoto puede ejecutar comandos arbitrarios sin autenticación previa. El exploit está disponible públicamente, elevando el riesgo de explotación en redes corporativas y proveedores de servicios en LATAM que utilizan este modelo como router/punto de acceso.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-77031] A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreat…
A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-77019] A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an …
A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-77020] A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by thi…
A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
20/08/2026
[CVE-2026-76998] A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0.…
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-77004] A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi…
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been published and may be used.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-76996] A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impact…
A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-76990] A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue …
A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-76783] A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown …
A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-76762] A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an …
A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-76764] A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an un…
A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76760] A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the f…
A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of the argument exec results in code injection. The attack may be performed from remote. The exploit has been made public and could be used. The reported GitHub issue was closed automatically due to inactivity.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76591] A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function …
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76582] A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/syst…
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component ssi. Executing a manipulation of the argument ipaddr can lead to command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76583] A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is a…
A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76574] A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the …
A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76221] GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator …
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next g…