Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
15/08/2026
Inyección SQL sin autenticación en plugin Object Sync for Salesforce
El plugin Object Sync for Salesforce para WordPress contiene una vulnerabilidad alta de inyección SQL (CVE-2026-15162, CVSS 7.5) que permite a atacantes no autenticados ejecutar comandos SQL a través del parámetro wordpress_object_type en la ruta /wp-json/object-sync-for-salesforce/push/. La falta de validación de permisos y nonce expone directamente a empresas mexicanas y latinoamericanas que integran Salesforce con WordPress, comprometiendo bases de datos de clientes y datos sensibles de negocio.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19680] A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut…
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19825] A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. Th…
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-15205] The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplie…
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user c…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19764] A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up…
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73408] Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mys…
Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backtick and stacked statement in its name could wait for a Budibase administrator to run schema discovery, causing the second statement to execute. The fix…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72853] Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's p…
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-16961] IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafte…
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
M Alto vulnerabilidad
13/08/2026
[CVE-2024-58374] Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet en…
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying…
M Alto vulnerabilidad
13/08/2026
[CVE-2019-25765] ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthent…
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. Exploitation e…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59109] SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in re…
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Da…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73670] A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authentica…
A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform table traversal, time-based blind, boolean-based blind, and error-based injection techniques to enumerate full database sch…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19710] A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vuln…
A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73346] Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66658] Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
Subscriber SQL Injection in Reviewer

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66430] Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28184] Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.
Subscriber SQL Injection in Form Maker by 10Web
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28168] Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
Subscriber SQL Injection in CubeWP
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28156] Subscriber SQL Injection in Do Lasso <= 358 versions.
Subscriber SQL Injection in Do Lasso
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28002] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22.