Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90854] A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. …
A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90855] A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This …
A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90849] A security vulnerability has been detected in SourceCodester College Notes Gallery Management System…
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90846] A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknow…
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90844] A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affe…
A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90841] A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by thi…
A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be u…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90809] A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function Ex…
A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection. It is possible to launch the attack remotely. The name of the patch is af582246f141311d574551b7571a517bcc3df750. It is best practice to apply a pat…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90805] A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07e…
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90789] A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue i…
A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
14/09/2026
Inyección SQL alta en Yot CMS hasta versión 3.3.1 — CVE-2026-90708
Se identificó una vulnerabilidad de inyección SQL en el manejador de cookies de Yot CMS versión 3.3.1 y anteriores. El parámetro yot3_user/yot3_pass en la función Login del archivo global.php permite ataques remotos sin autenticación. El exploit público incrementa el riesgo para sitios web y portales corporativos en LATAM que usan esta plataforma.
M Alto vulnerabilidad
14/09/2026
Inyección SQL alta en online-clinic-management-system afecta sistemas de salud
Se detectó una vulnerabilidad de inyección SQL en el archivo listdoctor.php del sistema online-clinic-management-system (hasta versión e9ee77a8827a1446220fa07ee693dc4d9a29a578) que permite manipulación remota del parámetro searchtext. El exploit es público y activo. Clínicas y sistemas de gestión médica en México y LATAM que utilizan este software están expuestos a acceso no autorizado a datos de pacientes y médicos.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90526] A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0.…
A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de inyección SQL en SourceCodester School Registration and Fee System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System 1.0 que afecta el archivo /bilal/normal/delete_stud.php. Un atacante remoto puede manipular el parámetro selector[] para ejecutar comandos SQL arbitrarios y comprometer bases de datos de instituciones educativas. La vulnerabilidad tiene CVSS 7.3 y exploits públicos disponibles, representando riesgo inmediato para sistemas de registro y gestión de matrículas en centros educativos de LATAM.
M Alto vulnerabilidad
13/09/2026
Inyección SQL alta en SourceCodester School Registration and Fee System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System 1.0 en el archivo /bilal/normal/pay_report.php, permitiendo manipulación del parámetro 'period' para ejecutar comandos SQL arbitrarios. El exploit es público y explotable remotamente, afectando directamente instituciones educativas en México y LATAM que utilizan este sistema para gestión de matrículas y cobros. Con CVSS 7.3, requiere acción inmediata en entornos de producción.
M Alto vulnerabilidad
13/09/2026
Inyección SQL alta en SourceCodester School Registration and Fee System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System versión 1.0, específicamente en el archivo /bilal/normal/save_stud.php. Un atacante remoto puede manipular el parámetro Status para ejecutar comandos SQL maliciosos y comprometer la base de datos de estudiantes y registros académicos. Esta vulnerabilidad es especialmente alta para instituciones educativas en México y LATAM que utilizan este sistema para gestionar matrículas y cobros de colegios.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90495] A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function…
A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of the argument auth leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-87925] A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc…
A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipulation of the argument pro_name[] results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87921] A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5…
A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_category/cid/update_brand/update_product leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. …
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87572] Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had comp…
Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-65669] Improper neutralization of special elements in output used by a downstream component ('injection') i…
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.