Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105919] A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff7…
A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of the component Administrator Login Endpoint. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit has been made public and could be…
M Alto vulnerabilidad
Hace 3 días
Inyección SQL alta en Kusalkasilva Learning-Management-System compromete credenciales
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en el endpoint de login de Kusalkasilva Learning-Management-System que permite manipular los parámetros de usuario y contraseña para acceder no autorizado a bases de datos. La falla reside en la función mysql_error del archivo login.php y puede ser explotada remotamente sin autenticación previa. Este riesgo es alta para instituciones educativas y corporativas en LATAM que usen este LMS, exponiendo registros académicos, datos personales y credenciales de usuarios.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-42414] Subscriber SQL Injection in ListingPro <= 2.9.12 versions.
Subscriber SQL Injection in ListingPro
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-42416] Subscriber SQL Injection in UDesign Core <= 4.15.0 versions.
Subscriber SQL Injection in UDesign Core
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39771] Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
Subscriber SQL Injection in Buddyboss Platform
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39747] Subscriber SQL Injection in Woffice <= 5.4.35 versions.
Subscriber SQL Injection in Woffice
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-32580] Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.
Unauthenticated SQL Injection in WooCommerce Lottery

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-32581] Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.
Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105317] Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
Subscriber SQL Injection in Paid Member Subscriptions
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-25434] Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions.
Subscriber SQL Injection in WP2LEADS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105807] A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an u…
A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105776] A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to…
A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. T…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105471] A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757…
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105469] A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca…
A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql injection. The attack may be launched remotely. The exploit has been publicly discl…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105470] A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca…
A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105468] A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d3…
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. This pro…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103066] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105386] A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling releas…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105387] A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757…
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105384] A vulnerability was found in UNION HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d1…
A vulnerability was found in UNION HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected is an unknown function of the file patient_info.php. Performing a manipulation of the argument patient_id results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy t…