Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
Inyección SQL alta en Yot CMS hasta versión 3.3.1 — CVE-2026-90708
Se identificó una vulnerabilidad de inyección SQL en el manejador de cookies de Yot CMS versión 3.3.1 y anteriores. El parámetro yot3_user/yot3_pass en la función Login del archivo global.php permite ataques remotos sin autenticación. El exploit público incrementa el riesgo para sitios web y portales corporativos en LATAM que usan esta plataforma.
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta de inyección SQL en EFence de Thinking Software Technology (CVSS 7.5)
EFence, producto de Thinking Software Technology, contiene una vulnerabilidad de inyección SQL que permite a atacantes no autenticados ejecutar comandos SQL arbitrarios y acceder al contenido de bases de datos. Esta falla expone sistemas de gestión de datos en empresas de LATAM sin requerir credenciales previas, comprometiendo la confidencialidad de información sensible. El riesgo es elevado en organizaciones que utilizan EFence en producción con acceso remoto.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82232] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-86460] Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search condi…
Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
M Alto vulnerabilidad
14/09/2026
Inyección SQL alta en online-clinic-management-system afecta sistemas de salud
Se detectó una vulnerabilidad de inyección SQL en el archivo listdoctor.php del sistema online-clinic-management-system (hasta versión e9ee77a8827a1446220fa07ee693dc4d9a29a578) que permite manipulación remota del parámetro searchtext. El exploit es público y activo. Clínicas y sistemas de gestión médica en México y LATAM que utilizan este software están expuestos a acceso no autorizado a datos de pacientes y médicos.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90526] A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0.…
A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de inyección SQL en SourceCodester School Registration and Fee System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System 1.0 que afecta el archivo /bilal/normal/delete_stud.php. Un atacante remoto puede manipular el parámetro selector[] para ejecutar comandos SQL arbitrarios y comprometer bases de datos de instituciones educativas. La vulnerabilidad tiene CVSS 7.3 y exploits públicos disponibles, representando riesgo inmediato para sistemas de registro y gestión de matrículas en centros educativos de LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/09/2026
Inyección SQL alta en SourceCodester School Registration and Fee System 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System 1.0 en el archivo /bilal/normal/pay_report.php, permitiendo manipulación del parámetro 'period' para ejecutar comandos SQL arbitrarios. El exploit es público y explotable remotamente, afectando directamente instituciones educativas en México y LATAM que utilizan este sistema para gestión de matrículas y cobros. Con CVSS 7.3, requiere acción inmediata en entornos de producción.
M Alto vulnerabilidad
13/09/2026
Inyección SQL alta en SourceCodester School Registration and Fee System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System versión 1.0, específicamente en el archivo /bilal/normal/save_stud.php. Un atacante remoto puede manipular el parámetro Status para ejecutar comandos SQL maliciosos y comprometer la base de datos de estudiantes y registros académicos. Esta vulnerabilidad es especialmente alta para instituciones educativas en México y LATAM que utilizan este sistema para gestionar matrículas y cobros de colegios.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90495] A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function…
A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of the argument auth leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted…
M Alto vulnerabilidad
12/09/2026
Inyección SQL en plugin rtMedia para WordPress afecta versiones hasta 4.7.11
El plugin rtMedia para WordPress, BuddyPress y bbPress es vulnerable a inyección SQL ciega basada en tiempo a través del parámetro 'compare' en todas las versiones hasta la 4.7.11. Atacantes no autenticados pueden ejecutar consultas SQL adicionales explotando insuficiente validación de entrada. Esta vulnerabilidad afecta especialmente a sitios de medios, redes sociales corporativas y comunidades en línea operadas por empresas mexicanas y latinoamericanas.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-84047] The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parame…
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-80491] The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input befor…
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62112] Editor SQL Injection in Amelia <= 2.4.9 versions.
Editor SQL Injection in Amelia
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62109] Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
Editor SQL Injection in Sky Addons for Elementor

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-72708] SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitem…
SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the pattern of a word character followed by an open parenthesis. Attackers can supply a crafted value such as a time-based paylo…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-82583] NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute ar…
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-15462] The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields'…
The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-18561] The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'ad…
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbati…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-73698] FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple admin…
FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate raw array values directly into an INSERT statement without parameterization. Because the underlying PDO connection uses emulated prepared statement…