Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 118 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1785
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-78245] A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_upl…
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-78244] A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this iss…
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-10582] Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRem…
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actua…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-75931] fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input …
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input d…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-75975] fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validat…
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, whic…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-78314] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-78315] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-78316] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-78317] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Crítico vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-66897] A path traversal vulnerability in LXD's instance template processing allows an attacker with contain…
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using …
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-75899] fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and th…
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name …
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-78202] A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_setting…
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.
M Alto vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-78201] A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the funct…
A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-78199] A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is a…
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
M Alto vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-78198] A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0.…
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-59561] Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulne…
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-78197] A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulner…
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-78182] A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environmen…
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to sql injection. Remote exploitation of the attack is possible. The exploit has bee…
M Crítico vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-78211] 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. …
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-78212] 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. U…
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.