Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 7357 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1263
Esta semana
RSS
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en Internship Management System 1.0 afecta formularios de autenticación
Se ha identificado una vulnerabilidad de inyección SQL en el componente de formulario de login administrativo (/admin/login.php) del sistema Internship Management System versión 1.0. Un atacante remoto puede manipular el parámetro de contraseña para ejecutar comandos SQL no autorizados, comprometiendo la integridad de bases de datos de gestión de practicantes en instituciones educativas y empresas de LATAM. La vulnerabilidad tiene un score CVSS de 7.3 y ya cuenta con exploits públicos disponibles.
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en Internship Management System 1.0 de code-projects
Se identificó una vulnerabilidad de inyección SQL en el archivo /login.php del sistema de gestión de prácticas Internship Management System 1.0, permitiendo manipulación remota del parámetro Password. El exploit público incrementa el riesgo de acceso no autorizado a bases de datos en instituciones educativas y empresas de LATAM que utilicen esta plataforma. Con CVSS 7.3, representa una amenaza significativa para credenciales y datos de estudiantes.
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se detectó una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0, específicamente en el archivo /reviewer_0/admins/assessments/subject/btn_functions.php mediante manipulación del parámetro ID. El exploit es público y puede ser explotado remotemente sin autenticación. Instituciones educativas y empresas que utilizan este sistema para evaluación de código en México y Latinoamérica están en riesgo inmediato de acceso no autorizado a bases de datos.
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0, específicamente en el parámetro ID del archivo btn_functions.php?action=remove. Un atacante remoto puede manipular este parámetro para ejecutar comandos SQL arbitrarios, comprometiendo la integridad y confidencialidad de las bases de datos académicas. El exploit está públicamente disponible y representa un riesgo inmediato para instituciones educativas en LATAM que utilizan este sistema.
M Alto vulnerabilidad
20/09/2026
Credenciales hardcodeadas en aiyiyi121 SxDevOps 1.0/1.1 (CVE-2026-93970)
Se ha identificado una vulnerabilidad de severidad alta (CVSS 7.3) en aiyiyi121 SxDevOps 1.0 y 1.1 que expone credenciales hardcodeadas en el archivo backend/sxdevops/settings.py del componente Settings Handler. La falla permite acceso remoto sin autenticación y afecta principalmente a equipos DevOps que utilizan esta plataforma en infraestructuras altas de México y Latinoamérica. El parche identificado es 2b4bf8585c3e731e7a8af30801ea46680bc783f9.
M Alto vulnerabilidad
20/09/2026
Inyección SQL alta en SourceCodester Online Reviewer Management System 1.0
Se detectó una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0 a través del parámetro courseID en el archivo /reviewer_0/admins/assessments/course/btn_functions.php. La falla permite ejecución remota de comandos SQL sin autenticación, comprometiendo bases de datos de evaluaciones académicas. El exploit está disponible públicamente, incrementando el riesgo para instituciones educativas y plataformas de gestión de contenido en Latinoamérica.
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta de credenciales hardcodeadas en aiyiyi121 SxDevOps 1.0/1.1
Se identificó una vulnerabilidad de severidad alta (CVSS 7.3) en aiyiyi121 SxDevOps versiones 1.0 y 1.1 que permite acceso remoto mediante credenciales hardcodeadas en la función ensure_default_superuser del archivo rbac/services.py. Esta falla compromete sistemas de control de acceso y gestión de infraestructura en empresas que utilizan este software en entornos cloud o on-premise en México y LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
20/09/2026
[CVE-2026-92540] The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce t…
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-92541] The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote…
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-82842] The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for …
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administ…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87067] The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instan…
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-81650] The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate…
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that exec…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-93962] A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element …
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Up…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-93959] A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue a…
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-93958] A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function syst…
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/09/2026
[CVE-2026-94056] Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers…
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-93990] Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allo…
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-93992] Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allow…
Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-93993] Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation p…
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de inyección de comandos en Totolik A3002MU
Se ha identificado una debilidad en el enrutador Totolik A3002MU versión Hh-B20211125.1046 que permite inyección de comandos remotos a través del parámetro localPin en la función formWsc del archivo /boafrm/formWsc. La vulnerabilidad tiene puntuación CVSS 9.9 (crítica) y ya cuenta con exploits públicamente disponibles, exponiendo a empresas en LATAM que utilizan este dispositivo a acceso no autorizado e infiltración de redes.