Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Alto vulnerabilidad
30/07/2026
[CVE-2026-22620] Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware…
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-58046] Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user t…
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-13395] The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize…
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-48448] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-69945] kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php…
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-69949] kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php v…
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-67403] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-67404] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-67405] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_passwo…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-67406] https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. …
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate office management system. Unsanitized user input in the specified parameter is i…
M Alto vulnerabilidad
29/07/2026
[CVE-2025-67407] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_studen…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-67408] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.ph…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-69942] kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient…
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-69943] kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the pa…
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-65340] kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsrep…
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/07/2026
[CVE-2026-5490] DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attacke…
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string befo…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-51992] SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to ex…
SQL Injection vulnerability in ClickHouse Server Versions
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-63229] A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated att…
A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-63230] A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticat…
A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-63231] A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker t…
A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover.