Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,734
Total alertas
3105
Críticas
10357
Altas
8
Ransomware
1762
Esta semana
RSS
M Alto vulnerabilidad
10/08/2026
CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Medio vulnerabilidad
10/08/2026
CVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Microsoft publica advisory de seguridad: CVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability.
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-19053] The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter bef…
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18470] The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset requ…
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18946] The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copyin…
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17022] The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's o…
The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17541] The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST…
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17542] The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its f…
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-14206] The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the e…
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19384] A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected…
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19387] A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element…
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code ex…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19389] Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly…
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information …
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19381] A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacte…
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted e…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19379] A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the …
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19376] A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function…
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue repor…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/08/2026
[CVE-2026-19374] A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593a…
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maint…
M Alto vulnerabilidad
09/08/2026
[CVE-2026-19355] A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl…
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about th…
M Alto vulnerabilidad
09/08/2026
Inyección SQL alta en node-sql-query afecta aplicaciones Node.js
Se identificó una vulnerabilidad de inyección SQL (CVE-2026-19351) en las versiones 0.1.25 a 0.1.28 de la librería node-sql-query de dresende. La falla reside en el manejador de parámetros de solicitud dentro de las funciones SelectQuery.from y SelectQuery.build (lib/Select.js), permitiendo ataques remotos sin autenticación. El exploit es público y afecta a aplicaciones web y APIs en producción que utilicen esta librería.
M Crítico vulnerabilidad
09/08/2026
Inyección de comandos crítica en repetidor Wi-Fi Aitemi M300 (CVE-2026-19348)
Se ha identificado una vulnerabilidad crítica (CVSS 9.8) en el repetidor Wi-Fi Aitemi M300 (versión r0-ea7890a) que permite inyección de comandos remotos a través de manipulación de parámetros en la función sprintf del archivo /protocol.csp. Un atacante puede explotar este defecto sin autenticación para ejecutar comandos arbitrarios en el dispositivo. El exploit ya es público, elevando significativamente el riesgo para infraestructuras de conectividad en México y Latinoamérica.
M Alto vulnerabilidad
09/08/2026
Vulnerabilidad alta de inyección de comandos en Tenda CH22 1.0.0.1
Se identificó una vulnerabilidad de inyección de comandos (CVE-2026-19346, CVSS 8.8) en el router Tenda CH22versión 1.0.0.1, específicamente en la función formCertListInfo del endpoint /goform/CertListInfo. Un atacante remoto puede manipular el parámetro Name para ejecutar comandos arbitrarios sin autenticación. Esta vulnerabilidad está públicamente divulgada y es activamente explotada en ataques.