Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-75986] A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element i…
A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the component Password Recovery. Such manipulation of the argument txtUserName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-54348] Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.upd…
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types. When the poisoned account later calls IpsAndPorts.listing, lib/Froxlor/Api/Commands/IpsAndPorts.php decodes the array an…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-74015] Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73392] Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Unauthenticated SQL Injection in Super Store Finder
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73365] Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
Unauthenticated SQL Injection in JetAppointment
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73345] Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
Customer SQL Injection in License Manager for WooCommerce
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73355] Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Unauthenticated SQL Injection in Affiliates Manager

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73339] Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73187] Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
Unauthenticated SQL Injection in Sticky Chat Widget
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-66622] Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
Unauthenticated SQL Injection in Depicter Slider
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-32466] Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
Subscriber SQL Injection in Gravity Forms Bookings premium
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-75778] A vulnerability was identified in code-projects Task Management System 1.0. This affects the functio…
A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75089] A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue…
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the argument email causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75079] A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnera…
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75080] A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. …
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-64657] Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector …
Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path statement without escaping embedded double quotes, allowing an authenticated administrator who saves or tests the datasource to execute arbitrary SQL through the simple …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-65822] ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, …
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to extract sensitive information and manipulate database queries. This issue is fixed in …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75014] A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability aff…
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-51346] SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote att…
SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.
M Alto vulnerabilidad
16/08/2026
Inyección SQL alta en plugin The Gallery by BestWebSoft para WordPress (versiones ≤4.7.9)
El plugin The Gallery by BestWebSoft para WordPress contiene una vulnerabilidad de inyección SQL (CVE-2026-2497, CVSS 7.2) en el parámetro '_gallery_order_{post_id}' que afecta todas las versiones hasta la 4.7.9. La falta de escape y sanitización de datos POST permite a atacantes ejecutar consultas SQL maliciosas. Esta vulnerabilidad expone datos sensibles en sitios web empresariales y e-commerce en México y Latinoamérica que utilizan este plugin.