Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54596] ITFlow provides an IT documentation, ticketing and accounting system for small managed service provi…
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the frequency parameter handled by agent/post/recurring_invoice.php. The handler passes recurring_invoice_frequency through sanitizeInput but interpolates it unquoted…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54597] ITFlow provides an IT documentation, ticketing and accounting system for small managed service provi…
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of the share_generate_link handler in agent/ajax.php. sanitizeInput applies string-context escaping, but…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54354] MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS…
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml__type=Integer are configured, but it does not verify that attacker-controlled CGI qstring or OGC API Features featureId inpu…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-52851] Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user …
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permission(LinkedHashMap) in src/main/java/org/traccar/model/Permission.java validates only the first two keys, but DatabaseStorage.removePermission() in …
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92926] A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects t…
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-93292] SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel ana…
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66631] Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
Administrator SQL Injection in MC Woocommerce Wishlist

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66625] Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
Administrator SQL Injection in WC Vendors Marketplace
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66626] Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
Editor SQL Injection in SKT Addons for Elementor
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66628] Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
Shop manager SQL Injection in WP-Lister Lite for eBay
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66630] Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
Administrator SQL Injection in PublishPress Series
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66624] Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
Administrator SQL Injection in WPMasterToolKit
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66618] Administrator SQL Injection in WP Maps <= 4.9.9 versions.
Administrator SQL Injection in WP Maps
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66619] Administrator SQL Injection in Newsletters <= 4.18 versions.
Administrator SQL Injection in Newsletters
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66580] Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
Contributor SQL Injection in Product Feed Manager

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92903] Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-control…
Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a malicious project configuration file or craft command-line input can cause Snowflake CLI to execute attacker-controlled SQL statements in the context of the victim's Snowf…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76425] A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQ…
A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endp…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20344] A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an au…
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have a valid account on the device with the role of Security Approver, Access Admin, or Network Admin. This vulnerability is due to insufficient validation o…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20300] A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection …
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affecte…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20247] A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injectio…
A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to modify data in the underlying database.