Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0, específicamente en el parámetro ID del archivo btn_functions.php?action=remove. Un atacante remoto puede manipular este parámetro para ejecutar comandos SQL arbitrarios, comprometiendo la integridad y confidencialidad de las bases de datos académicas. El exploit está públicamente disponible y representa un riesgo inmediato para instituciones educativas en LATAM que utilizan este sistema.
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se detectó una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0 a través del parámetro courseID en el archivo /reviewer_0/admins/assessments/course/btn_functions.php. La falla permite ejecución remota de comandos SQL sin autenticación, comprometiendo bases de datos de evaluaciones académicas. El exploit está disponible públicamente, incrementando el riesgo para instituciones educativas y plataformas de gestión de contenido en Latinoamérica.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-93959] A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue a…
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de inyección de comandos en Totolik A3002MU
Se ha identificado una debilidad en el enrutador Totolik A3002MU versión Hh-B20211125.1046 que permite inyección de comandos remotos a través del parámetro localPin en la función formWsc del archivo /boafrm/formWsc. La vulnerabilidad tiene puntuación CVSS 9.9 (crítica) y ya cuenta con exploits públicamente disponibles, exponiendo a empresas en LATAM que utilizan este dispositivo a acceso no autorizado e infiltración de redes.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución remota de código en plugin WP Photo Album Plus para WordPress
El plugin WP Photo Album Plus para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones debido a sanitización insuficiente en nombres de archivo cargados. La vulnerabilidad reside en la función wppa_image_magick, donde escapeshellcmd() se aplica al comando completo en lugar de entrecomillar argumentos individuales antes de ejecutar comandos ImageMagick via exec(). Esto afecta directamente a sitios WordPress en México y Latinoamérica que dependen de este plugin para galerías de fotos.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93371] A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue aff…
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The name of the patch is c7ad3bd79c7c52…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-87701] Improper neutralization of special elements in output used by a downstream component ('injection') i…
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92926] A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects t…
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20130] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by C…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92406] A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted ele…
A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92405] A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. Th…
A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92366] A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part…
A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-12351] IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0…
IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-12355] IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3…
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91848] A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function artic…
A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91004] A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted e…
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90879] A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown …
A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue re…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90880] A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function s…
A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90876] A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by th…
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90877] A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this is…
A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.