Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1780
Esta semana
RSS
M Alto vulnerabilidad
30/07/2026
[CVE-2026-12562] The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug int…
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that power…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-68500] Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.…
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID t…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-68502] LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.15…
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and subprocess.call(command, shell=True), allowing unauthenticated remote code execution in the C2 process. This issue is fixed in…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-68503] LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.15…
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-66418] OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthent…
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive C…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-66803] Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a ne…
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-52539] Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environmen…
Outstatic CMS

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-35847] An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping …
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69933] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69934] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69935] CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and reven…
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69936] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69937] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpo…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69938] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the param…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69941] SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=…
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69947] SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-69930] CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.…
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
M Crítico vulnerabilidad
30/07/2026
[CVE-2025-65336] Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price…
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-67594] Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthen…
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root pass…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-67206] Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController tha…
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger executio…