Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1763
Esta semana
RSS
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-35847] An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping …
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69933] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69934] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69935] CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and reven…
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69936] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69937] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpo…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69938] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the param…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69941] SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=…
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69947] SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69930] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-65336] Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price…
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-67594] Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthen…
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root pass…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-67206] Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController tha…
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger executio…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-67207] Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController t…
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without admin…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-67208] Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remo…
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-67527] OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/wo…
OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve Storages::FileLink records by raw id, detach or hard-delete existing FileLinks, and re-parent FileLinks from other projects to an attacker-controlled work packa…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-11536] IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability i…
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-12946] IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the …
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-66415] Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that al…
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC AP…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-66416] Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attac…
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, P…