Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 370 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105184] A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted…
A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted element is an unknown function of the file /admin/creteria.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105295] GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates …
GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid certificate once can intercept later automatic update checks, offer a fake version, and execute code as the user upon installation.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105175] A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some …
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105293] Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allow…
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outsi…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105172] A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is …
A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105169] A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca…
A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the component Take Order Handler. The manipulation of the argument order_id/delivery_person_id results in sql injection. It is possible to launch the attack remotely. Th…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105170] A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the p…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105166] A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145…
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The e…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105167] A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument location can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be u…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105219] Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the …
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-105209] ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: wh…
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and r…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105210] ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted…
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, a…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105211] ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauth…
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105213] ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentica…
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105158] A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function …
A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105148] A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code…
A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was c…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105149] A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown proces…
A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105147] A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the com…
A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but di…
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad XSS reflejado alta en WP Statistics versiones anteriores a 14.16.15
Se ha identificado una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en el plugin WP Statistics para WordPress, utilizado ampliamente en sitios corporativos y de comercio electrónico en Latinoamérica. Un atacante puede inyectar código malicioso que se ejecute en el navegador de usuarios autenticados, comprometiendo sesiones, robando credenciales o instalando malware. Esta vulnerabilidad afecta versiones desde la inicial hasta la 14.16.14.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad XSS reflejado alta en Unlimited Elements for Elementor hasta versión 2.0.20
Se ha identificado una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en el plugin Unlimited Elements for Elementor (versiones hasta 2.0.20) que permite a atacantes inyectar código malicioso durante la generación de páginas web. Esta vulnerabilidad afecta principalmente a sitios WordPress en México y LATAM que utilizan este plugin de widgets y addons. Con un CVSS de 7.1, el riesgo es considerable para plataformas de comercio electrónico, portales corporativos y sitios de contenido que dependen de Elementor.