Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-51346] SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote att…
SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-48528] Metacat is data repository software that helps researchers preserve, share, and discover data. Metac…
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input that can be passed through to the backend SQL database. The `nodeId` parameter can be modified to inject SQL commands, an…
M Crítico vulnerabilidad
14/08/2026
Inyección SQL crítica en SiYuan v3.7.2 y anteriores permite ejecución de comandos
SiYuan versiones 3.7.2 y anteriores contienen una vulnerabilidad de inyección SQL en la función de búsqueda de referencias inversas y menciones. El fallo radica en la concatenación insegura de metadatos de bloques (título, nombre, alias, texto de anclaje) con palabras clave del cliente en consultas SQL, escapando solo comillas dobles pero no simples. Un atacante puede inyectar comillas simples para ejecutar comandos SQL arbitrarios, comprometiendo la integridad y confidencialidad de bases de datos locales en sistemas Windows, macOS y Linux.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72851] Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered …
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66472] Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
Unauthenticated SQL Injection in Everest Backup
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66478] Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
Unauthenticated SQL Injection in Church Admin
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66458] Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
Unauthenticated SQL Injection in RealPress

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66436] Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66446] Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Subscriber SQL Injection in If-So Dynamic Content Personalization
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-61969] Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Unauthenticated SQL Injection in Listdom
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-61966] Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Subscriber SQL Injection in WPJAM Basic
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28001] Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated SQL Injection in WP Directory Kit
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28142] Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Unauthenticated SQL Injection in Web Directory Free
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73300] Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Bu…
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.
M Crítico vulnerabilidad
12/08/2026
Inyección SQL ciega crítica en Essekia Tablesome Table versiones hasta 1.2.9
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-66659) en Essekia Tablesome Table que permite a atacantes ejecutar consultas SQL no autorizadas sin necesidad de ver respuestas directas (SQL Injection Ciega). Esta falla afecta a organizaciones en México y Latinoamérica que utilizan este componente para gestión de tablas en aplicaciones web, exponiendo bases de datos críticas a acceso no autorizado, robo de datos sensibles y manipulación de registros.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73211] PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.upda…
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-48381] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not req…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73069] Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty al…
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing buildSqlColumnDefinition in packages/twenty-server/src/engine/twenty-orm/…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-46670] YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection i…
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.
M Crítico vulnerabilidad
11/08/2026
Inyección SQL crítica en e107 2.4.0 permite acceso no autenticado a bases de datos
Una vulnerabilidad de inyección SQL en e107 2.4.0 permite a atacantes no autenticados ejecutar comandos SQL arbitrarios a través del parámetro de ID de noticia, comprometiendo completamente la integridad de la base de datos. Los atacantes pueden leer, modificar o eliminar todos los contenidos, incluidas credenciales de administrador. Esta falla afecta directamente a portales de contenidos, sitios informativos y plataformas comunitarias desplegadas en LATAM sin parches aplicados.