Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 8 horas
Buscando: "X" — 3719 resultados ✕ Limpiar búsqueda
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1029
Esta semana
RSS
M Crítico vulnerabilidad
14/08/2026
Vulnerabilidad crítica en plugin Grav API permite escalación de privilegios
El plugin getgrav/grav-plugin-api anterior a la versión 1.0.13 no valida correctamente que los permisos de nuevas claves API sean un subconjunto de los permisos del solicitante. Un atacante con una clave API de bajo privilegio puede crear claves con permisos elevados, comprometiendo aplicaciones Grav alojadas en México y Latinoamérica. Esta vulnerabilidad afecta directamente portales de contenido, sistemas de gestión documental y plataformas educativas que utilizan este plugin.
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad alta de inyección de plantillas en Grav CMS anterior a 2.0.13
Grav CMS versiones anteriores a 2.0.13 contiene una vulnerabilidad de inyección de plantillas del lado del servidor (SSTI) en parámetros de email-action que permite a editores con permisos bajos ejecutar comandos arbitrarios del sistema operativo. Los atacantes pueden inyectar payloads Twig usando el filtro find sin sandbox en campos de asunto, cuerpo, destinatario u origen de correos, logrando ejecución remota de código cuando se envían formularios. Esta vulnerabilidad afecta principalmente a portales web, sistemas de gestión de contenidos y plataformas de formularios en empresas latinoamericanas.
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad alta de ejecución remota de código en Grav CMS 2.0.12 y anteriores
Grav CMS versiones anteriores a 2.0.13 contiene una vulnerabilidad de ejecución remota de código (RCE) en la validación de configuración del plugin Flex Objects. Un atacante autenticado puede eludir la validación de nombres mediante notación de arreglos y cargar un archivo ZIP malicioso con código PHP, escribiendo archivos ejecutables en el directorio raíz web. Esta vulnerabilidad afecta directamente a portales, sitios dinámicos y plataformas de gestión de contenidos en organizaciones de México y Latinoamérica que utilizan esta CMS.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19822] A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the…
A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
14/08/2026
Inyección SQL crítica en SiYuan v3.7.2 y anteriores permite ejecución de comandos
SiYuan versiones 3.7.2 y anteriores contienen una vulnerabilidad de inyección SQL en la función de búsqueda de referencias inversas y menciones. El fallo radica en la concatenación insegura de metadatos de bloques (título, nombre, alias, texto de anclaje) con palabras clave del cliente en consultas SQL, escapando solo comillas dobles pero no simples. Un atacante puede inyectar comillas simples para ejecutar comandos SQL arbitrarios, comprometiendo la integridad y confidencialidad de bases de datos locales en sistemas Windows, macOS y Linux.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19821] A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the …
A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19815] A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is th…
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19814] A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setM…
A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19794] The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to…
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19812] A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function U…
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19813] A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts th…
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19811] A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element i…
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19792] A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapp…
A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the publ…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19791] A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addS…
A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for att…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19789] A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects th…
A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19790] A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPo…
A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPorts leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19788] A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_devi…
A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-18109] The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Aut…
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only expl…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19771] A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown fun…
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure bu…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19762] A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Pat…
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation of the argument Name results in path traversal. The attack may be launched remotely. The exploit has been made public and could be used.