Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105385] A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transaction_details.php. Executing a manipulation of the argument transaction_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utiliz…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105383] A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This impacts an unknown function of the file php/controller.php. Such manipulation of the argument transaction_idS leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling relea…
M Alto vulnerabilidad
Hace 4 días
SQL Injection alta en itsourcecode Online Admission System 1.0 expone datos de admisiones
Se identificó una vulnerabilidad de inyección SQL en el archivo /admin/login1.php del sistema de admisiones en línea itsourcecode versión 1.0, permitiendo a atacantes remotos manipular el parámetro User para acceder no autorizado a bases de datos. Esta falla afecta directamente a instituciones educativas en LATAM que utilizan esta solución para gestionar procesos de admisión de estudiantes. El exploit ha sido públicamente divulgado, elevando significativamente el riesgo de explotación inmediata.
M Alto vulnerabilidad
Hace 4 días
Inyección SQL ciega en Groundhogg afecta versiones hasta 4.8.3
Se identificó una vulnerabilidad de inyección SQL ciega (CVE-2026-104408, CVSS 7.6) en el plugin Groundhogg para WordPress que permite a atacantes ejecutar consultas SQL maliciosas sin validación adecuada. Esta falla afecta principalmente a empresas en LATAM que usan Groundhogg para automatización de marketing y gestión de contactos, comprometiendo la confidencialidad e integridad de bases de datos. El riesgo es alta en entornos con acceso público al plugin sin autenticación reforzada.
M Alto vulnerabilidad
Hace 4 días
Inyección SQL ciega en Sirv versiones anteriores a 8.2.6 permite acceso no autorizado
Se identificó una vulnerabilidad de inyección SQL ciega en la plataforma Sirv que afecta versiones hasta la 8.2.5. Un atacante podría explotar esta falla para extraer datos sensibles de bases de datos sin autenticación válida. Empresas en LATAM que utilizan Sirv para gestión de contenido, catálogos de productos o sistemas de e-commerce están en riesgo inmediato.
M Alto vulnerabilidad
Hace 4 días
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0, específicamente en el parámetro 'Subject' del archivo btn_functions.php. La vulnerabilidad permite a atacantes remotos ejecutar comandos SQL maliciosos sin autenticación, comprometiendo bases de datos de instituciones educativas y empresas que utilicen este sistema. El exploit ha sido divulgado públicamente, aumentando el riesgo inmediato de explotación.
M Alto vulnerabilidad
Hace 4 días
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0, específicamente en el parámetro Subject del archivo btn_functions.php?action=update. La vulnerabilidad permite a atacantes remotos manipular consultas SQL y comprometer la integridad de bases de datos. El exploit está públicamente disponible y afecta principalmente a instituciones educativas y plataformas de evaluación académica en LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105231] A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72…
A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is an unknown function of the file admin/signup.php of the component Admin Registration. The manipulation of the argument email/username/location results in sql injection. It is possible to launch the attack remotely. The exp…
M Alto vulnerabilidad
Hace 4 días
Inyección SQL alta en sistema de gestión de residuos food-waste-management-system
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-105232, CVSS 7.3) en el archivo deliverysignup.php del componente de página de registro del sistema food-waste-management-system. Un atacante remoto puede manipular los parámetros username, email o location para ejecutar comandos SQL arbitrarios. Esta vulnerabilidad afecta sistemas de gestión de residuos implementados en restaurantes, cadenas de comida rápida y empresas de distribución en LATAM que utilicen esta plataforma.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105230] A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb8289…
A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument delivery_person_id/order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclo…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105229] A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument email/name/gender can lead to sql injection. The attack may be performed from remote. The ex…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105185] A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown fu…
A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105182] A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacte…
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105183] A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is …
A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105184] A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted…
A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted element is an unknown function of the file /admin/creteria.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105175] A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some …
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105172] A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is …
A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105169] A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca…
A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the component Take Order Handler. The manipulation of the argument order_id/delivery_person_id results in sql injection. It is possible to launch the attack remotely. Th…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105166] A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145…
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The e…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105167] A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument location can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be u…