Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 3240 resultados ✕ Limpiar búsqueda
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1806
Esta semana
RSS
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad de autorización en plugin Flex Objects afecta CMS Grav
El plugin Flex Objects (versiones hasta 1.4.6) en Grav CMS contiene un fallo de control de acceso en su API que permite a usuarios autenticados con permisos básicos ejecutar operaciones sin validar restricciones de campo, usuario o administrador. Afecta principalmente a sitios que exponen la Flex API sin restricciones de red. Empresas en LATAM usando Grav para portales internos o públicos deben verificar su configuración de permisos inmediatamente.
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad de escalada de privilegios alta en plugin API de Grav (CVE-2026-72833)
El plugin API de Grav en versiones 1.0.6 a 1.0.11 permite a atacantes con claves API limitadas escalar privilegios y acceder a funciones administrativas restringidas en controladores de grupos, cuentas, preferencias y widgets. Esta vulnerabilidad afecta portales, sitios colaborativos y aplicaciones Grav desplegadas en infraestructuras LATAM que utilizan autenticación API para integraciones.
M Alto vulnerabilidad
14/08/2026
Plugin Grav API: bypas de restricción de scopes en endpoint de reportes (CVE-2026-72825)
El plugin getgrav/grav-plugin-api anterior a versión 1.0.13 contiene una vulnerabilidad que permite eludir las restricciones de scope de API keys. Un atacante con credenciales de API limitadas puede ejecutar operaciones de configuración a nivel administrador en el endpoint POST /reports/twig-content/allowlist, comprometiendo la integridad de sistemas Grav en producción. Afecta especialmente a plataformas de contenido desplegadas en México y LATAM que exponen APIs internas.
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad alta de inyección de plantillas en Grav CMS anterior a 2.0.13
Grav CMS versiones anteriores a 2.0.13 contiene una vulnerabilidad de inyección de plantillas del lado del servidor (SSTI) en parámetros de email-action que permite a editores con permisos bajos ejecutar comandos arbitrarios del sistema operativo. Los atacantes pueden inyectar payloads Twig usando el filtro find sin sandbox en campos de asunto, cuerpo, destinatario u origen de correos, logrando ejecución remota de código cuando se envían formularios. Esta vulnerabilidad afecta principalmente a portales web, sistemas de gestión de contenidos y plataformas de formularios en empresas latinoamericanas.
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad alta de ejecución remota de código en Grav CMS 2.0.12 y anteriores
Grav CMS versiones anteriores a 2.0.13 contiene una vulnerabilidad de ejecución remota de código (RCE) en la validación de configuración del plugin Flex Objects. Un atacante autenticado puede eludir la validación de nombres mediante notación de arreglos y cargar un archivo ZIP malicioso con código PHP, escribiendo archivos ejecutables en el directorio raíz web. Esta vulnerabilidad afecta directamente a portales, sitios dinámicos y plataformas de gestión de contenidos en organizaciones de México y Latinoamérica que utilizan esta CMS.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19822] A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the…
A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19821] A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the …
A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19815] A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is th…
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19814] A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setM…
A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19794] The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to…
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19812] A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function U…
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19813] A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts th…
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19811] A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element i…
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-18039] The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied reg…
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-15205] The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplie…
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user c…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19792] A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapp…
A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the publ…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19791] A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addS…
A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for att…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19789] A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects th…
A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19790] A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPo…
A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPorts leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19788] A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_devi…
A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.