Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
Inyección SQL alta en sistema de gestión de residuos food-waste-management-system
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-105232, CVSS 7.3) en el archivo deliverysignup.php del componente de página de registro del sistema food-waste-management-system. Un atacante remoto puede manipular los parámetros username, email o location para ejecutar comandos SQL arbitrarios. Esta vulnerabilidad afecta sistemas de gestión de residuos implementados en restaurantes, cadenas de comida rápida y empresas de distribución en LATAM que utilicen esta plataforma.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105230] A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb8289…
A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument delivery_person_id/order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclo…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105229] A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument email/name/gender can lead to sql injection. The attack may be performed from remote. The ex…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105185] A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown fu…
A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105182] A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacte…
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105183] A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is …
A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105184] A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted…
A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted element is an unknown function of the file /admin/creteria.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105175] A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some …
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105172] A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is …
A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105169] A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca…
A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the component Take Order Handler. The manipulation of the argument order_id/delivery_person_id results in sql injection. It is possible to launch the attack remotely. Th…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105166] A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145…
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The e…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105167] A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument location can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be u…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105158] A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function …
A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through a…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105149] A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown proces…
A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in…
M Crítico vulnerabilidad
Hace 5 días
Inyección de código crítica en InternLM MindSearch 0.1.0 afecta agente planificador
Se ha identificado una vulnerabilidad crítica (CVSS 10.0) en InternLM MindSearch 0.1.0 que permite inyección de código remota a través de manipulación de argumentos en la función ExecutionAction.run del componente Planner Agent. La vulnerabilidad ha sido divulgada públicamente y cuenta con exploits disponibles. Sistemas en México y LATAM que utilicen esta versión están expuestos a compromisos totales de confidencialidad, integridad y disponibilidad.