Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1741
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
Inyección SQL en WP w3all phpBB <= 3.0.5 afecta cuentas de suscriptores
Se ha identificado una vulnerabilidad de inyección SQL en WP w3all phpBB versiones 3.0.5 y anteriores que permite a usuarios suscritos ejecutar comandos SQL arbitrarios. Esta falla (CVSS 8.5) impacta directamente sitios WordPress que integran foros phpBB, afectando potencialmente bases de datos de clientes, transacciones y datos sensibles. En LATAM, donde muchos portales de e-commerce y comunidades online utilizan esta integración, la exposición es alta.
M Crítico vulnerabilidad
Hace 3 días
Inyección SQL sin autenticación en Directory Pro <= 2.5.8
Se ha identificado una vulnerabilidad crítica de inyección SQL sin autenticación en Directory Pro versión 2.5.8 y anteriores (CVSS 9.3), que permite a atacantes ejecutar comandos SQL arbitrarios contra bases de datos expuestas. Esta vulnerabilidad afecta directamente a empresas en México y Latinoamérica que utilicen este software para gestionar directorios corporativos, comprometiendo la confidencialidad e integridad de datos sensibles. El riesgo es crítico dado que no requiere credenciales para su explotación.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66680] Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66609] Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in TheGem (Elementor)
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66592] Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66593] Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-66594] Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WordPress Persistent Login

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2025-15688] Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in Capella
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76783] A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown …
A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76762] A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an …
A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76764] A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an un…
A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76574] A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the …
A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-61518] ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id pa…
ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requests in its default configuration. A remote AP…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-20030] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements us…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-71176] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76205] phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpo…
phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-70422] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-56088] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-16019] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73388] Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Unauthenticated SQL Injection in Nikstore Core