Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
25/09/2026
[CVE-2026-44642] Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_…
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_magic_quotes_gpc function exists, so PHP 8 and later concatenate an unauthenticated username directly into the upgrade authentication SQL query. When database upgrade…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-33639] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter r…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84893] IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticat…
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-77874] IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerab…
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta de inyección SQL en DIAEnergie anterior a versión 1.11.00.022
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-78309, CVSS 8.8) en DIAEnergie que afecta versiones anteriores a la 1.11.00.022. Esta falla permite a atacantes ejecutar comandos SQL no autorizados, comprometiendo la confidencialidad e integridad de bases de datos en sistemas energéticos altas de la región. Empresas en México y Latinoamérica que utilicen esta plataforma enfrentan riesgo elevado de exfiltración de datos y manipulación de registros operacionales.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta de inyección SQL en DIAEnergie versiones anteriores a 1.11.00.022
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-78311, CVSS 8.8) en DIAEnergie que afecta versiones anteriores a la 1.11.00.022. Esta falla permite a atacantes ejecutar comandos SQL maliciosos, comprometiendo la confidencialidad e integridad de bases de datos en sistemas de gestión energética. Empresas en México y Latinoamérica que utilicen esta plataforma deben actuar inmediatamente para evitar acceso no autorizado a datos altas de operaciones.
M Alto vulnerabilidad
24/09/2026
Inyección SQL alta en java110 MicroCommunity 2.0 expone servidores empresariales
Se identificó una vulnerabilidad de inyección SQL (CVSS 7.3) en java110 MicroCommunity versiones hasta 2.0, específicamente en el endpoint fallBack API de BusinessApi.java. Un atacante remoto puede manipular el parámetro fallBackSql para ejecutar comandos SQL arbitrarios, comprometiendo bases de datos en servidores corporativos. El exploit está públicamente disponible y ya es utilizado en ataques activos.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96751] A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a081…
A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96604] A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the functi…
A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did n…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96601] A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of t…
A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version informati…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96602] A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file…
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continu…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96826] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Injection. This issue affects W4 Post List: from n/a through 3.0.6.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-95601] Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
Unauthenticated SQL Injection in Product Filter by WBW
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95590] Subscriber SQL Injection in Tainacan <= 1.2.0 versions.
Subscriber SQL Injection in Tainacan
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95593] Editor SQL Injection in Ultimeter <= 3.0.8 versions.
Editor SQL Injection in Ultimeter

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95522] Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
Shop manager SQL Injection in Easy Digital Downloads
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94174] Administrator SQL Injection in Email Log <= 2.63 versions.
Administrator SQL Injection in Email Log
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94124] Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.
Contributor SQL Injection in WP EasyCart
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93773] Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
Contributor SQL Injection in Mollie Forms
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93527] Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
Contributor SQL Injection in Live Copy Paste for Elementor