Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 5 min
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
996
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0, específicamente en el parámetro 'Subject' del archivo btn_functions.php. La vulnerabilidad permite a atacantes remotos ejecutar comandos SQL maliciosos sin autenticación, comprometiendo bases de datos de instituciones educativas y empresas que utilicen este sistema. El exploit ha sido divulgado públicamente, aumentando el riesgo inmediato de explotación.
M Alto vulnerabilidad
Hace 4 días
Papermerge 3.5.3: Ejecución remota de código mediante traversal de directorios
Papermerge versión 3.5.3 permite a usuarios estándar ejecutar código remoto explotando traversal de directorios en el endpoint /api/documents/upload. Un atacante puede escribir archivos Python .pth en site-packages que se ejecutan al reiniciar el intérprete, comprometiendo servidores de gestión documental en empresas LATAM. La vulnerabilidad afecta principalmente a organizaciones que confían en Papermerge para procesamiento de documentos sensibles.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad SSRF alta en ChatGPTNextWeb NextChat hasta versión 2.16.1
Se ha identificado una vulnerabilidad de Server-Side Request Forgery (SSRF) en ChatGPTNextWeb NextChat versiones hasta 2.16.1, ubicada en la función proxyHandler del componente Proxy Fallback Handler (app/api/proxy.ts). Un atacante remoto puede manipular el argumento x-base-url para ejecutar solicitudes HTTP arbitrarias desde el servidor afectado, potencialmente comprometiendo datos internos, accediendo a servicios de red privados o saltando controles de seguridad perimetral. La explotación es remota y código de prueba ya está disponible públicamente.
M Alto vulnerabilidad
Hace 4 días
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0, específicamente en el parámetro Subject del archivo btn_functions.php?action=update. La vulnerabilidad permite a atacantes remotos manipular consultas SQL y comprometer la integridad de bases de datos. El exploit está públicamente disponible y afecta principalmente a instituciones educativas y plataformas de evaluación académica en LATAM.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105231] A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72…
A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is an unknown function of the file admin/signup.php of the component Admin Registration. The manipulation of the argument email/username/location results in sql injection. It is possible to launch the attack remotely. The exp…
M Alto vulnerabilidad
Hace 5 días
Inyección SQL alta en sistema de gestión de residuos food-waste-management-system
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-105232, CVSS 7.3) en el archivo deliverysignup.php del componente de página de registro del sistema food-waste-management-system. Un atacante remoto puede manipular los parámetros username, email o location para ejecutar comandos SQL arbitrarios. Esta vulnerabilidad afecta sistemas de gestión de residuos implementados en restaurantes, cadenas de comida rápida y empresas de distribución en LATAM que utilicen esta plataforma.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105230] A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb8289…
A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument delivery_person_id/order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclo…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105229] A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f…
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument email/name/gender can lead to sql injection. The attack may be performed from remote. The ex…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105185] A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown fu…
A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105182] A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacte…
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105183] A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is …
A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105184] A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted…
A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted element is an unknown function of the file /admin/creteria.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-20586] In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to r…
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9614.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-20524] In apu, there is a possible memory corruption due to improper input validation. This could lead to l…
In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-20526] In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to …
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01898195; Issue ID: MSV-8906.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-20531] In apu, there is a possible memory corruption due to use after free. This could lead to local escala…
In apu, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249016; Issue ID: MSV-9169.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-20519] In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to …
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-20520] In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to …
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-20521] In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could …
In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11375674; Issue ID: MSV-9571.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-20522] In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lea…
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172.