Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-52348] cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
M Alto vulnerabilidad
17/07/2026
[CVE-2026-44739] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, …
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through CustomReportController:columnConfigAction, SqlAdapter::getColumns, SqlAdapter::buildQueryString, and Db::fetchAssociative(), allowing an attacke…
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-8297] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.
M Alto vulnerabilidad
17/07/2026
[CVE-2026-16014] A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unkno…
A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
O Alto vulnerabilidad
17/07/2026
[CVE-2026-62238] OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint cross…
OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data…
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-38158] A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 all…
A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.
M Alto vulnerabilidad
16/07/2026
[CVE-2025-45868] LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonSer…
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12753] The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable t…
The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15907] A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of…
A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulne…
M Crítico vulnerabilidad
15/07/2026
[CVE-2026-52887] NocoBase is an AI-powered no-code/low-code platform for building business applications and enterpris…
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authen…
A Alto vulnerabilidad
15/07/2026
[CVE-2026-56287] A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/…
A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. This can be leveraged …
A Alto vulnerabilidad
15/07/2026
[CVE-2026-57821] A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in…
A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduc…
A Alto vulnerabilidad
15/07/2026
[CVE-2026-35152] A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint)…
A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthori…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-15804] The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can …
The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data.
M Alto vulnerabilidad
15/07/2026
[CVE-2026-12512] The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied…
The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Crítico vulnerabilidad
14/07/2026
[CVE-2026-48324] ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQ…
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
A Alto vulnerabilidad
14/07/2026
[CVE-2026-47992] Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command …
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploi…
S Alto vulnerabilidad
14/07/2026
[CVE-2026-45073] Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr…
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion sco…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47295] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47296] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.