Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1799
Esta semana
RSS
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20269] Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthentica…
Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20268] Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauth…
Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive database information including database names and table structures.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20263] Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unau…
Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_focalpoint, view=location, and a crafted id parameter containing SQL commands to extract sensitive database information.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20264] Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticat…
Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_sponsorwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information including crede…
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20265] Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated …
Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_flipwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20266] Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated att…
Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to extract sensitive database information.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20267] Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthe…
Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database information.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20255] Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated at…
Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter. Attackers can send GET requests to index.php with the option=com_bookpro and view=popup parameters, injecting SQL commands in the visatype parameter to extract sensitive database information includin…
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20256] Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated…
Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter to extract sensitive database information.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20257] Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthentica…
Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract sensitive information.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20258] Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows…
Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_pofos&view=pofo&id=[SQL] to extract sensitive database information.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20259] Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attacke…
Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract sensitive database information including credentials and configuration data.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20260] Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthentica…
Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL payloads in the product_id parameter to extract sensitive database information including credentials and configuration d…
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20261] Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauth…
Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20262] Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated …
Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters to extract sensitive database information including table names and column structures.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20253] Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticate…
Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection payloads to extract sensitive database information including credentials and system data.
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20254] Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated…
Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userid parameter. Attackers can send GET requests to index.php with the option=com_userbench&view=detail&userid parameter containing SQL injection payloads to extract sensitive database information including credenti…
M Alto vulnerabilidad
19/06/2026
[CVE-2017-20252] Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated atta…
Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information.
P Alto vulnerabilidad
19/06/2026
[CVE-2026-12044] SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<descripti…
SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS ''`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead o…
P Crítico vulnerabilidad
19/06/2026
[CVE-2026-12045] Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence data…
Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ ONLY wrapper to prevent data modification. The LLM-supplied query was forwarded to…