Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28156] Subscriber SQL Injection in Do Lasso <= 358 versions.
Subscriber SQL Injection in Do Lasso
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28001] Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated SQL Injection in WP Directory Kit
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28002] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28142] Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Unauthenticated SQL Injection in Web Directory Free
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27538] Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated SQL Injection in WP Directory Kit
M Alto vulnerabilidad
13/08/2026
[CVE-2026-15741] SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a s…
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-11840] Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions be…
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73331] CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated at…
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing SQL syntax that the database backend evaluates as part of an inadequately parameterized query. Attackers can supply malicious slug payloads using boolean- or union-style blind SQL injection techniques to extra…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73332] CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin tha…
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in vic…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72807] SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view t…
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim's kernel when the package is i…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17111] IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially c…
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73300] Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Bu…
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-44741] Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18…
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL expression without parameterization or allowlist validation. Versiosn 2.3.6 and 1.7.1…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17418] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
M Crítico vulnerabilidad
12/08/2026
Inyección SQL ciega crítica en Essekia Tablesome Table versiones hasta 1.2.9
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-66659) en Essekia Tablesome Table que permite a atacantes ejecutar consultas SQL no autorizadas sin necesidad de ver respuestas directas (SQL Injection Ciega). Esta falla afecta a organizaciones en México y Latinoamérica que utilizan este componente para gestión de tablas en aplicaciones web, exponiendo bases de datos críticas a acceso no autorizado, robo de datos sensibles y manipulación de registros.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18474] The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before u…
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18230] The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before u…
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18057] The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled val…
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16977] The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-contr…
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13613] The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied para…
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.