Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad
Hace 5 días
Inyección SQL ciega crítica en Unlimited Elements for Elementor (CVSS 9.3)
Vulnerabilidad de inyección SQL en el plugin Unlimited Elements for Elementor (versiones hasta 2.0.20) permite a atacantes ejecutar consultas maliciosas contra bases de datos de sitios WordPress. Afecta principalmente a agencias digitales y empresas en LATAM que utilizan este plugin de diseño para construir landing pages y portales. El impacto es crítico: acceso no autorizado a datos sensibles, robo de credenciales y compromiso total del sitio.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-62071] Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
Unauthenticated SQL Injection in WordPress File Upload
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103248] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filt…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-18782] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-82307] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-96822] Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
Unauthenticated SQL Injection in Books Gallery
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-72507] The "reportType" parameter in the product summary report feature within the balancing reports sectio…
The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-72510] The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-bas…
The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-68954] The "pattern" parameter used in search function in the home page of the TMS application is vulnerabl…
The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-68068] The "screenID" parameter in the electronic transaction queue viewer feature within the manual transa…
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-63713] The "search" parameter in the view audit logs feature within the utilities section is susceptible to…
The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2023-54400] Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that al…
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-62262] Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earl…
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL. include/ws_functions/pwg.images.php stores the unvalidated value in the search rules, and include/functions_search.inc.php integer-cas…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-95601] Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
Unauthenticated SQL Injection in Product Filter by WBW
M Crítico vulnerabilidad
23/09/2026
[CVE-2025-63564] SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to ex…
SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-75682] Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command (…
Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploita…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-82009] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary SQL commands. Exploitation of this issue does not require user interaction. Scope is …
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-82010] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-82011] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. Sco…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-12718] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported.