Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78247] A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affec…
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
24/08/2026
Inyección SQL alta en FluentCRM Pro versiones <= 3.1.12
Se ha identificado una vulnerabilidad de inyección SQL en FluentCRM Pro que afecta versiones hasta la 3.1.12, permitiendo a atacantes ejecutar comandos SQL arbitrarios a través del módulo de autoría. Esta vulnerabilidad impacta directamente a empresas en México y Latinoamérica que utilizan esta plataforma de automatización de marketing para gestionar datos de contactos y campañas sensibles.
M Alto vulnerabilidad
24/08/2026
Inyección SQL alta en itsourcecode Online Clinic Management System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en el módulo de login administrativo (success/login.php) de itsourcecode Online Clinic Management System versión 1.0, permitiendo ejecución remota no autenticada mediante manipulación del parámetro Username. La vulnerabilidad ha sido divulgada públicamente (CVSS 7.3) y afecta directamente a clínicas y centros médicos en LATAM que utilizan este sistema para gestionar datos sensibles de pacientes.
M Alto vulnerabilidad
24/08/2026
Inyección SQL alta en ProLancer Element versiones ≤ 1.4.8
Se ha identificado una vulnerabilidad de inyección SQL en ProLancer Element que afecta todas las versiones hasta la 1.4.8, con puntuación CVSS de 8.5 (alta). Esta falla permite a atacantes ejecutar consultas SQL arbitrarias a través del módulo de suscriptores, comprometiendo la integridad y confidencialidad de bases de datos. Empresas en LATAM que utilizan esta plataforma para gestión de proyectos o freelancing están expuestas a robo de datos sensibles y acceso no autorizado.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-32478] Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Subscriber SQL Injection in WP Project Manager Pro
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78244] A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this iss…
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78314] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78315] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78316] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78317] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78201] A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the funct…
A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78199] A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is a…
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78198] A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0.…
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78197] A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulner…
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78182] A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environmen…
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to sql injection. Remote exploitation of the attack is possible. The exploit has bee…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78171] A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vuln…
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/processlogin.php. The manipulation of the argument User leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
23/08/2026
[CVE-2026-78143] A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. A…
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-46682] BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica…
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala. The method interpolated those values into breakout room visibility queries, allowing arbitrary SQL exe…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-77019] A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an …
A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-77020] A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by thi…
A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.