Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de inyección SQL en plugin All-in-One WP Migration and Backup
El plugin All-in-One WP Migration and Backup para WordPress (versiones hasta 7.109) contiene una vulnerabilidad de inyección SQL en la funcionalidad de restauración de archivos, explotable sin autenticación debido a escaping insuficiente de parámetros. Afecta a miles de sitios WordPress en LATAM que utilizan este plugin para migraciones y backups, permitiendo a atacantes ejecutar consultas SQL arbitrarias y comprometer bases de datos completas.
M Alto vulnerabilidad
25/08/2026
Inyección SQL alta en plugin Readabler para WordPress afecta versiones hasta 2.0.18
El plugin Readabler para WordPress contiene una vulnerabilidad de inyección SQL que afecta todas las versiones anteriores a 2.0.18, permitiendo a atacantes no autenticados ejecutar consultas SQL maliciosas para extraer información sensible de bases de datos. Esta vulnerabilidad representa un riesgo alto para sitios WordPress en LATAM que alojan contenido confidencial, datos de clientes o información empresarial alta.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78568] The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and i…
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive informa…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-32554] Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-32555] Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78248] A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is…
A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76848] TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression …
TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array and interpolates the result into the generated statement as SELECT DISTINCT ON (values), with no escaping, quoting, identifier validation or allowlist, an…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78247] A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affec…
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
24/08/2026
Inyección SQL alta en FluentCRM Pro versiones <= 3.1.12
Se ha identificado una vulnerabilidad de inyección SQL en FluentCRM Pro que afecta versiones hasta la 3.1.12, permitiendo a atacantes ejecutar comandos SQL arbitrarios a través del módulo de autoría. Esta vulnerabilidad impacta directamente a empresas en México y Latinoamérica que utilizan esta plataforma de automatización de marketing para gestionar datos de contactos y campañas sensibles.
M Alto vulnerabilidad
24/08/2026
Inyección SQL alta en itsourcecode Online Clinic Management System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en el módulo de login administrativo (success/login.php) de itsourcecode Online Clinic Management System versión 1.0, permitiendo ejecución remota no autenticada mediante manipulación del parámetro Username. La vulnerabilidad ha sido divulgada públicamente (CVSS 7.3) y afecta directamente a clínicas y centros médicos en LATAM que utilizan este sistema para gestionar datos sensibles de pacientes.
M Alto vulnerabilidad
24/08/2026
Inyección SQL alta en ProLancer Element versiones ≤ 1.4.8
Se ha identificado una vulnerabilidad de inyección SQL en ProLancer Element que afecta todas las versiones hasta la 1.4.8, con puntuación CVSS de 8.5 (alta). Esta falla permite a atacantes ejecutar consultas SQL arbitrarias a través del módulo de suscriptores, comprometiendo la integridad y confidencialidad de bases de datos. Empresas en LATAM que utilizan esta plataforma para gestión de proyectos o freelancing están expuestas a robo de datos sensibles y acceso no autorizado.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-32478] Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Subscriber SQL Injection in WP Project Manager Pro
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-32551] Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Unauthenticated SQL Injection in Woo Essential
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78244] A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this iss…
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78314] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78315] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78316] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78317] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78201] A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the funct…
A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78199] A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is a…
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.