Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1739
Esta semana
RSS
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19963] A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function sta…
A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19962] A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setW…
A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respo…
M Alto vulnerabilidad
16/08/2026
[CVE-2026-19960] A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function form…
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
16/08/2026
Inyección SQL alta en Evergreen afecta componente OpenSRF Gateway
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en Evergreen versiones hasta 3.14.11, 3.15.11, 3.16.5 y 3.17-beta1. La falla reside en la función desconocida del archivo /osrf-gateway-v1 del servicio open-ils.fielder, permitiendo manipulación remota sin autenticación. Bibliotecas digitales, sistemas de gestión documental y plataformas educativas en LATAM que usan Evergreen están expuestas a exfiltración de datos sensibles.
M Alto vulnerabilidad
16/08/2026
[CVE-2026-19919] A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown funct…
A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19905] A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHS…
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but…
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19899] A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected…
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19825] A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. Th…
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19764] A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up…
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond …
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-19747] A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14…
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19710] A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vuln…
A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-12618] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19384] A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected…
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
09/08/2026
[CVE-2026-19355] A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl…
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about th…
M Alto vulnerabilidad
09/08/2026
Inyección SQL alta en node-sql-query afecta aplicaciones Node.js
Se identificó una vulnerabilidad de inyección SQL (CVE-2026-19351) en las versiones 0.1.25 a 0.1.28 de la librería node-sql-query de dresende. La falla reside en el manejador de parámetros de solicitud dentro de las funciones SelectQuery.from y SelectQuery.build (lib/Select.js), permitiendo ataques remotos sin autenticación. El exploit es público y afecta a aplicaciones web y APIs en producción que utilicen esta librería.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
09/08/2026
Inyección de comandos crítica en repetidor Wi-Fi Aitemi M300 (CVE-2026-19348)
Se ha identificado una vulnerabilidad crítica (CVSS 9.8) en el repetidor Wi-Fi Aitemi M300 (versión r0-ea7890a) que permite inyección de comandos remotos a través de manipulación de parámetros en la función sprintf del archivo /protocol.csp. Un atacante puede explotar este defecto sin autenticación para ejecutar comandos arbitrarios en el dispositivo. El exploit ya es público, elevando significativamente el riesgo para infraestructuras de conectividad en México y Latinoamérica.
M Alto vulnerabilidad
09/08/2026
Vulnerabilidad alta de inyección de comandos en Tenda CH22 1.0.0.1
Se identificó una vulnerabilidad de inyección de comandos (CVE-2026-19346, CVSS 8.8) en el router Tenda CH22versión 1.0.0.1, específicamente en la función formCertListInfo del endpoint /goform/CertListInfo. Un atacante remoto puede manipular el parámetro Name para ejecutar comandos arbitrarios sin autenticación. Esta vulnerabilidad está públicamente divulgada y es activamente explotada en ataques.
M Alto vulnerabilidad
09/08/2026
Inyección SQL alta en Task Management System 1.0 permite acceso remoto a bases de datos
Se ha identificado una vulnerabilidad de inyección SQL en code-projects Task Management System 1.0 a través del parámetro task_id en el archivo /user/comment_count_user.php. Esta falla permite a atacantes remotos comprometer la integridad y confidencialidad de datos, siendo especialmente alta para empresas en LATAM que gestionan información sensible de proyectos. El exploit ha sido divulgado públicamente, aumentando el riesgo inmediato de explotación.
M Alto vulnerabilidad
09/08/2026
Inyección SQL alta en Task Management System 1.0 de code-projects
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-19343, CVSS 7.3) en code-projects Task Management System 1.0 a través del archivo /admin/AdminLogin.php. Un atacante remoto puede manipular los parámetros de email/password para ejecutar comandos SQL arbitrarios y comprometer la integridad de bases de datos. El exploit está disponible públicamente, lo que aumenta significativamente el riesgo para empresas mexicanas y latinoamericanas que utilizan este sistema.
M Alto vulnerabilidad
08/08/2026
Inyección de comandos alta en INQUIRELAB mcp-bridge-api (CVE-2026-19263)
Se identificó una vulnerabilidad de inyección de comandos en el componente Servers Endpoint del archivo mcp-bridge.js de INQUIRELAB mcp-bridge-api. Un atacante remoto podría manipular los parámetros command/args para ejecutar comandos arbitrarios en servidores afectados. Esta vulnerabilidad impacta directamente sistemas de integración de APIs en infraestructuras empresariales de México y Latinoamérica que utilizan esta librería en versiones anteriores a b30a82aa1d1d1139e0de846c41c8aadee6e06114.