Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1739
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75089] A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue…
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the argument email causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75079] A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnera…
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75080] A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. …
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-64657] Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector …
Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path statement without escaping embedded double quotes, allowing an authenticated administrator who saves or tests the datasource to execute arbitrary SQL through the simple …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-65822] ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, …
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to extract sensitive information and manipulate database queries. This issue is fixed in …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75014] A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability aff…
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
M Alto vulnerabilidad
16/08/2026
Inyección SQL alta en plugin The Gallery by BestWebSoft para WordPress (versiones ≤4.7.9)
El plugin The Gallery by BestWebSoft para WordPress contiene una vulnerabilidad de inyección SQL (CVE-2026-2497, CVSS 7.2) en el parámetro '_gallery_order_{post_id}' que afecta todas las versiones hasta la 4.7.9. La falta de escape y sanitización de datos POST permite a atacantes ejecutar consultas SQL maliciosas. Esta vulnerabilidad expone datos sensibles en sitios web empresariales y e-commerce en México y Latinoamérica que utilizan este plugin.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/08/2026
Inyección SQL alta en Evergreen afecta componente OpenSRF Gateway
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en Evergreen versiones hasta 3.14.11, 3.15.11, 3.16.5 y 3.17-beta1. La falla reside en la función desconocida del archivo /osrf-gateway-v1 del servicio open-ils.fielder, permitiendo manipulación remota sin autenticación. Bibliotecas digitales, sistemas de gestión documental y plataformas educativas en LATAM que usan Evergreen están expuestas a exfiltración de datos sensibles.
M Alto vulnerabilidad
16/08/2026
[CVE-2026-19919] A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown funct…
A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19905] A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHS…
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but…
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19899] A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected…
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
15/08/2026
Inyección SQL sin autenticación en plugin Object Sync for Salesforce
El plugin Object Sync for Salesforce para WordPress contiene una vulnerabilidad alta de inyección SQL (CVE-2026-15162, CVSS 7.5) que permite a atacantes no autenticados ejecutar comandos SQL a través del parámetro wordpress_object_type en la ruta /wp-json/object-sync-for-salesforce/push/. La falta de validación de permisos y nonce expone directamente a empresas mexicanas y latinoamericanas que integran Salesforce con WordPress, comprometiendo bases de datos de clientes y datos sensibles de negocio.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19680] A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut…
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19825] A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. Th…
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-15205] The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplie…
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user c…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19764] A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up…
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73408] Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mys…
Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backtick and stacked statement in its name could wait for a Budibase administrator to run schema discovery, causing the second statement to execute. The fix…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72853] Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's p…
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-16961] IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafte…
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
M Alto vulnerabilidad
13/08/2026
[CVE-2024-58374] Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet en…
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying…