Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81800] Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés)
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88890] OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter bui…
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analyti…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-9163] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-7188] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-87925] A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc…
A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipulation of the argument pro_name[] results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87921] A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5…
A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_category/cid/update_brand/update_product leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. …
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79322] SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-…
SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-67401] A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root thr…
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
M Alto vulnerabilidad
09/09/2026
Inyección SQL autenticada alta en SiYuan anterior a v3.8.2
SiYuan versiones anteriores a v3.8.2 contienen una vulnerabilidad de inyección SQL autenticada en el parámetro query method=1 del endpoint fullTextSearchBlock. Atacantes con acceso autenticado pueden ejecutar sentencias UNION SELECT para leer la tabla completa de bloques, exponiendo todo el contenido de documentos y atributos sensibles, independientemente de controles de publicación. Afecta especialmente a empresas en LATAM que utilizan SiYuan para gestión de conocimiento corporativo o bases de datos documentales.
M Alto vulnerabilidad
09/09/2026
Inyección SQL alta en Dell SCG 5.0 afecta sistemas de almacenamiento empresarial
Dell SCG 5.0 (versiones Appliance anteriores a 5.36.00.16 y Application anteriores a 5.36.00.00) contiene una vulnerabilidad de inyección SQL (CVSS 7.2) que permite a atacantes con privilegios elevados y acceso remoto comprometer la integridad de datos y obtener acceso no autorizado. Afecta principalmente a infraestructuras de almacenamiento en centros de datos de empresas medianas y grandes en LATAM.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-84068] The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before u…
The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-14962] The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and es…
The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87034] Tanium addressed a SQL injection vulnerability in Comply.
Tanium addressed a SQL injection vulnerability in Comply.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78623] The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into datab…
The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-75746] ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQ…
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69716] Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Of…
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-66819] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-66820] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67370] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62895] Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker t…
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.