Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73211] PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.upda…
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-48381] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not req…
M Alto vulnerabilidad
11/08/2026
[CVE-2016-20097] Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet…
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a SQL query. Attackers can control the markPath value returned by the query to supply an attacker-controlled filesystem path…
M Alto vulnerabilidad
11/08/2026
[CVE-2022-50997] Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPer…
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65673] CVET-EOP
CVET-EOP
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73069] Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty al…
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing buildSqlColumnDefinition in packages/twenty-server/src/engine/twenty-orm/…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-46670] YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection i…
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
Inyección SQL alta en Koha permite lectura de bases de datos a usuarios autenticados
Koha versiones 24.11.17, 25.05.12, 25.11.06 y 26.05.01 contiene una vulnerabilidad de inyección SQL en el módulo de adquisiciones (acqui/parcels.pl) que permite a personal autenticado con permisos de recepción de órdenes leer contenido arbitrario de la base de datos manipulando el parámetro 'orderby'. Esta exposición afecta directamente a bibliotecas, instituciones educativas y organismos públicos en LATAM que gestionan inventarios bibliográficos mediante Koha.
M Alto vulnerabilidad
11/08/2026
Inyección SQL almacenada en Koha permite lectura no autorizada de bases de datos
Una vulnerabilidad de inyección SQL almacenada afecta Koha versiones 24.11.17, 25.05.12, 25.11.06 y 26.05.01. Personal autenticado con permisos de modificación masiva de ítems puede ejecutar consultas SQL arbitrarias almacenando payloads en reglas automáticas, comprometiendo la confidencialidad de datos en sistemas bibliotecarios. Bibliotecas, instituciones educativas y organismos públicos en LATAM que usan Koha están potencialmente expuestos.
M Alto vulnerabilidad
11/08/2026
Inyección SQL alta en Pimcore admin-ui-classic-bundle afecta gestión de contenidos
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-72562) en Pimcore admin-ui-classic-bundle versión 2.3 y anteriores que permite a usuarios autenticados ejecutar comandos SQL arbitrarios a través del filtro de columna ID en la grilla DataObject. Un atacante con acceso al backend puede exfiltrar, modificar o eliminar bases de datos completas sin validación paramétrica. Esto afecta especialmente a medianas y grandes empresas en LATAM que utilizan Pimcore para gestión de activos digitales y catálogos de productos.
M Crítico vulnerabilidad
11/08/2026
Inyección SQL crítica en e107 2.4.0 permite acceso no autenticado a bases de datos
Una vulnerabilidad de inyección SQL en e107 2.4.0 permite a atacantes no autenticados ejecutar comandos SQL arbitrarios a través del parámetro de ID de noticia, comprometiendo completamente la integridad de la base de datos. Los atacantes pueden leer, modificar o eliminar todos los contenidos, incluidas credenciales de administrador. Esta falla afecta directamente a portales de contenidos, sitios informativos y plataformas comunitarias desplegadas en LATAM sin parches aplicados.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72558] An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the…
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72550] An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated re…
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW COLUMNS query via a bare PDO::query() call, enabling stacked statement injection. An unauthenticated attacker can read, modify, or delete the entire database.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19425] Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability…
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72898] Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password'…
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72899] Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or da…
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72731] Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026…
Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-staff members of a group a query is shared with, could craft parameter values that escaped the intended query and executed arbitrary SQL through plugins/discourse-data-explorer/lib/discourse_data_explo…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-63106] ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product l…
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL injection through the unsanitized rating parameter to extract the full database contents,…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72565] A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attacke…
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-19053] The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter bef…
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.