Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-15275] The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the '…
The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alr…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87767] The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and es…
The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87770] The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape para…
The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87771] The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape paramete…
The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87774] The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter…
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87775] The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter…
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-18912] ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection…
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-93426] SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the …
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54646] CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php …
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54647] CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php dir…
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQ…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54596] ITFlow provides an IT documentation, ticketing and accounting system for small managed service provi…
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the frequency parameter handled by agent/post/recurring_invoice.php. The handler passes recurring_invoice_frequency through sanitizeInput but interpolates it unquoted…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54597] ITFlow provides an IT documentation, ticketing and accounting system for small managed service provi…
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of the share_generate_link handler in agent/ajax.php. sanitizeInput applies string-context escaping, but…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54354] MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS…
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml__type=Integer are configured, but it does not verify that attacker-controlled CGI qstring or OGC API Features featureId inpu…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-52851] Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user …
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permission(LinkedHashMap) in src/main/java/org/traccar/model/Permission.java validates only the first two keys, but DatabaseStorage.removePermission() in …
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92926] A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects t…
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-93292] SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel ana…
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66631] Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
Administrator SQL Injection in MC Woocommerce Wishlist
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66625] Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
Administrator SQL Injection in WC Vendors Marketplace
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66626] Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
Editor SQL Injection in SKT Addons for Elementor
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66628] Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
Shop manager SQL Injection in WP-Lister Lite for eBay