Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95522] Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
Shop manager SQL Injection in Easy Digital Downloads
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94174] Administrator SQL Injection in Email Log <= 2.63 versions.
Administrator SQL Injection in Email Log
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94124] Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.
Contributor SQL Injection in WP EasyCart
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93773] Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
Contributor SQL Injection in Mollie Forms
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93527] Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
Contributor SQL Injection in Live Copy Paste for Elementor
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96514] A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the…
A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96673] Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that all…
Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86677] ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user t…
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
M Alto vulnerabilidad
23/09/2026
Inyección SQL alta en ManageEngine OpManager y Firewall Analyzer v12.8.669
ZohoCorp ManageEngine OpManager y Firewall Analyzer en versiones 12.8.669 e inferiores contienen una vulnerabilidad de inyección SQL en el módulo de búsqueda de reportes de reglas (CVSS 8.8). Esta falla permite a atacantes ejecutar comandos SQL maliciosos contra bases de datos de gestión de infraestructura, afectando la confidencialidad e integridad de datos de monitoreo y seguridad perimetral altas para empresas en LATAM.
M Alto vulnerabilidad
23/09/2026
Inyección SQL en plugin 'Rename wp-login.php' de WordPress afecta versiones hasta 2.0.1
El plugin 'Rename wp-login.php to anything you want' para WordPress contiene una vulnerabilidad de inyección SQL basada en tiempo en el parámetro 'log' (usuario) que permite a atacantes no autenticados ejecutar consultas SQL arbitrarias. Afecta todas las versiones hasta 2.0.1 debido a escape insuficiente de datos de entrada. El riesgo es alto en sitios WordPress empresariales en México y LATAM que utilicen este plugin para ofuscación de seguridad.
M Alto vulnerabilidad
23/09/2026
[CVE-2022-4997] The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a pay…
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95927] A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects…
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95926] A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted…
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of the argument test_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95924] A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is …
A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95925] A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected elem…
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96272] ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search end…
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-61685] ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list …
ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing unauthenticated attackers to inject SQL through crafted query string keys. Version 3.7.0…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95819] A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca…
A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolli…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18137] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execut…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65128] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQ…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.