Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85388] Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helpe…
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for …
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-82526] R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attacke…
R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execut…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85187] A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affe…
A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publ…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84813] Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
Unauthenticated SQL Injection in GeoDirectory
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84768] Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85138] A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file w…
A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85155] WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php …
WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can exploit this ordering oracle to infer password hash values and recovery tokens, and trigger SQL errors that disclose the f…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-81286] Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
Unauthenticated SQL Injection in WCFM Marketplace
M Alto vulnerabilidad
02/09/2026
[CVE-2026-14828] Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and A…
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84208] AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Loca…
AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement binding, allowing unauthenticated attackers to execute UNION-based SQL injection to read arbitrary database contents includi…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84111] A flaw has been found in Chanjet CRM up to 20260707. This issue affects some unknown processing of t…
A flaw has been found in Chanjet CRM up to 20260707. This issue affects some unknown processing of the file jxf_dump_table.php. This manipulation of the argument gblOrgID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-18630] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18210] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18765] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82922] A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects …
A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respon…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82914] A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability…
A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not re…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-81763] Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
Unauthenticated SQL Injection in Throws SPAM Away
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-81293] Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
Unauthenticated SQL Injection in WP Data Access
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-81756] Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81287] Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
Subscriber SQL Injection in Charitable