Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
19/08/2026
Inyección SQL alta en SourceCodester Simple Online Food Ordering System 1.0
Se identificó una vulnerabilidad de inyección SQL en el módulo de administración (/admin/ajax.php?action=delete_menu) del sistema de pedidos en línea SourceCodester versión 1.0. Un atacante remoto puede manipular el parámetro ID para ejecutar comandos SQL arbitrarios, comprometiendo la integridad y confidencialidad de bases de datos de restaurantes y datos de clientes. El exploit está públicamente disponible y afecta directamente a plataformas de delivery y comercio electrónico en LATAM.
M Alto vulnerabilidad
19/08/2026
Inyección SQL alta en SourceCodester Simple Online Food Ordering System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en el módulo de administración (/admin/ajax.php?action=save_menu) del sistema SourceCodester Simple Online Food Ordering System versión 1.0, permitiendo a atacantes remotos manipular consultas a base de datos mediante el parámetro ID. Esta afecta directamente a restaurantes y negocios de alimentos en LATAM que utilizan esta plataforma para gestionar menús y pedidos online. El exploit está disponible públicamente, elevando significativamente el riesgo de compromisos inmediatos.
M Alto vulnerabilidad
19/08/2026
Inyección SQL alta en SourceCodester Simple Online Food Ordering System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en SourceCodester Simple Online Food Ordering System 1.0 a través del parámetro Username en /admin/ajax.php?action=login. Un atacante remoto puede ejecutar comandos SQL maliciosos sin autenticación válida, comprometiendo bases de datos de órdenes, clientes y pagos. Esta vulnerabilidad afecta directamente a restaurantes, fondas y servicios de delivery en LATAM que utilicen este sistema de código abierto.
M Alto vulnerabilidad
19/08/2026
Vulnerabilidad alta de inyección de comandos en routers TRENDnet 1.1.02b01
Se ha identificado una falla de inyección de comandos en routers TRENDnet versión 1.1.02b01 a través del parámetro wan_type en /cgi-bin/ping.cgi. Un atacante remoto puede explotar esta vulnerabilidad sin autenticación para ejecutar comandos arbitrarios en el dispositivo. Esta falla afecta directamente infraestructuras de pequeñas y medianas empresas en LATAM que utilizan estos routers como punto de acceso perimetral.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-75986] A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element i…
A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the component Password Recovery. Such manipulation of the argument txtUserName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-75984] A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of th…
A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of the argument Hostname results in command injection. The attack can be launched remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75778] A vulnerability was identified in code-projects Task Management System 1.0. This affects the functio…
A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75089] A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue…
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the argument email causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75079] A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnera…
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75080] A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. …
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75014] A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability aff…
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19980] A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE930…
A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated re…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19963] A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function sta…
A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19962] A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setW…
A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respo…
M Alto vulnerabilidad
16/08/2026
[CVE-2026-19960] A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function form…
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/08/2026
Inyección SQL alta en Evergreen afecta componente OpenSRF Gateway
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en Evergreen versiones hasta 3.14.11, 3.15.11, 3.16.5 y 3.17-beta1. La falla reside en la función desconocida del archivo /osrf-gateway-v1 del servicio open-ils.fielder, permitiendo manipulación remota sin autenticación. Bibliotecas digitales, sistemas de gestión documental y plataformas educativas en LATAM que usan Evergreen están expuestas a exfiltración de datos sensibles.
M Alto vulnerabilidad
16/08/2026
[CVE-2026-19919] A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown funct…
A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19905] A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHS…
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but…
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19899] A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected…
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19825] A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. Th…
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.