Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96601] A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of t…
A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version informati…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96602] A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file…
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continu…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96514] A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the…
A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-19179] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipu…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-18875] IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unau…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payme…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95927] A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects…
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95926] A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted…
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of the argument test_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95924] A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is …
A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95925] A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected elem…
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95819] A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca…
A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolli…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94491] A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcas…
A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in an…
M Alto vulnerabilidad
21/09/2026
Inyección SQL alta en Drogon Framework hasta versión 1.9.13 afecta aplicaciones en LATAM
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en el componente ORM de Drogon Framework versiones hasta 1.9.13, específicamente en la función makeCriteria. Un atacante remoto puede manipular parámetros de filtrado para ejecutar consultas SQL no autorizadas. Empresas en LATAM que utilicen esta librería en aplicaciones web deben evaluar inmediatamente su exposición, especialmente en sistemas con acceso a bases de datos sensibles.
M Alto vulnerabilidad
21/09/2026
Inyección SQL alta en Drogon Framework hasta versión 1.9.13
Se detectó una vulnerabilidad de inyección SQL en el componente ORM Mapper de Drogon Framework (versiones hasta 1.9.13), específicamente en la función Mapper::orderBy. Un atacante remoto puede manipular parámetros de ordenamiento para ejecutar comandos SQL arbitrarios. El exploit es público y activo, afectando aplicaciones web desarrolladas con este framework que procesen entrada de usuarios sin validación adecuada.
M Alto vulnerabilidad
21/09/2026
Inyección de comandos alta en Router Feiyu Star B-MB5E202 afecta infraestructura de red
Se identificó una vulnerabilidad de inyección de comandos (CVSS 7.4) en el Router Feiyu Star modelo B-MB5E202-210322-r11656 de Chengdu Feiyuxing Technology. El fallo está en el manejador de cookies del archivo /send_order.cgi, donde la manipulación del parámetro session_id permite ejecución remota de comandos sin autenticación. Empresas en México y Latinoamérica que utilicen este equipo en perímetros de red enfrentan riesgo inmediato de compromiso total.
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad de inyección SQL alta en QCMS hasta versión 6.0.6
Se ha detectado una vulnerabilidad de inyección SQL (CVSS 7.3) en QCMS versiones hasta 6.0.6 que afecta la función self_Tmp en el componente Content Detail Page. Un atacante remoto puede manipular el parámetro ID para ejecutar comandos SQL no autorizados, especialmente porque el router procesa REQUEST_URI sin decodificación de URL. Este exploit ha sido divulgado públicamente y representa riesgo inmediato para portales de contenido y aplicaciones web en producción.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
20/09/2026
[CVE-2026-94015] A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unk…
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en SourceCodester Drug Recommendation System 1.0
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en SourceCodester Drug Recommendation System 1.0 a través del parámetro ID en /Admin/edit_symptom.php. La vulnerabilidad permite a atacantes remotos ejecutar comandos SQL arbitrarios y comprometer bases de datos de sistemas de salud. El exploit está disponible públicamente, incrementando significativamente el riesgo en instituciones médicas y farmacias en LATAM que utilicen este software.
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta de inyección de código en DedeCMS hasta versión 5.7.118
Se identificó una vulnerabilidad de inyección de código en DedeCMS versiones hasta 5.7.118, localizada en el archivo plus/mytag_js.php que permite manipulación remota del parámetro 'aid'. El exploit está públicamente disponible y representa un riesgo inmediato para sitios web y portales de contenido en México y Latinoamérica que utilizan este CMS. La vulnerabilidad permite ejecución de código arbitrario con impacto alta en la integridad y disponibilidad de aplicaciones web.
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en Internship Management System 1.0 afecta portales de gestión de pasantías
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en el archivo /employer/login.php del sistema de gestión de pasantías versión 1.0, permitiendo a atacantes remotos manipular credenciales y acceder a bases de datos de empresas. El exploit público incrementa el riesgo para instituciones educativas y corporativos en LATAM que utilizan este software para administrar programas de internados.
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en Internship Management System 1.0 afecta formularios de autenticación
Se ha identificado una vulnerabilidad de inyección SQL en el componente de formulario de login administrativo (/admin/login.php) del sistema Internship Management System versión 1.0. Un atacante remoto puede manipular el parámetro de contraseña para ejecutar comandos SQL no autorizados, comprometiendo la integridad de bases de datos de gestión de practicantes en instituciones educativas y empresas de LATAM. La vulnerabilidad tiene un score CVSS de 7.3 y ya cuenta con exploits públicos disponibles.