Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82701] A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue i…
A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-5956] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82615] A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affec…
A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::find_phone of the file /passwordrecover.php of the component Password Recovery Interface. The manipulation of the argument phonenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82614] A flaw has been found in itsourcecode Online Medicine Delivery System 1.0. This vulnerability affect…
A flaw has been found in itsourcecode Online Medicine Delivery System 1.0. This vulnerability affects the function loadResultList of the file /index.php?q=product of the component Product Category Filter Interface. Executing a manipulation of the argument Category can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82611] A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this…
A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used fo…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82612] A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affe…
A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item of the component Product Detail Page. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82613] A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the f…
A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the function loadResultList of the file /index.php?q=product of the component Product Search Interface. Performing a manipulation of the argument Search results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82610] A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. Affected is…
A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. Affected is the function Employee::employeeAuthentication of the file /rider/login.php of the component Login Interface. The manipulation of the argument emp_email results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82600] A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown fun…
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82655] Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list paramet…
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to extract database contents including password hashes and user credentials.
M Alto vulnerabilidad
29/08/2026
[CVE-2026-16061] The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from th…
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-77586] In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are pla…
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permission to write to a sampled MongoDB collection can choose a name that closes the quoted identifier early, so that additional SQL text becomes part of the gen…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55634] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82227] Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Contributor SQL Injection in WPBulky
M Alto vulnerabilidad
28/08/2026
[CVE-2026-40018] None None None No publicly available exploits are known.
None None None No publicly available exploits are known.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-5097] The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in …
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75417] A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() func…
A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an authenticated administrator to execute arbitrary SQL queries via boolean-based blind injectio…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81728] Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads …
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords, comment markers, parentheses, spaces and quotes intact. import_insert() in htdocs/core/modules/import/import_csv.modules.php …
M Alto vulnerabilidad
27/08/2026
Inyección SQL alta en WooCommerce <= 2.0.11 afecta tiendas en línea
Se identificó una vulnerabilidad de inyección SQL en el motor de sugerencias de WooCommerce versiones 2.0.11 y anteriores, que permite a usuarios contribuyentes ejecutar comandos SQL arbitrarios en bases de datos de tiendas. Esta falla afecta directamente a comercios electrónicos en México y Latinoamérica que dependen de este plugin para WordPress, exponiendo datos sensibles de clientes y transacciones.
M Alto vulnerabilidad
27/08/2026
Inyección SQL en Like Button Rating <= 2.6.61 afecta sitios WordPress
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-78285) en el plugin Like Button Rating versiones 2.6.61 y anteriores, con severidad alta (CVSS 8.5). Esta falla permite a usuarios autenticados ejecutar consultas SQL maliciosas, comprometiendo la integridad y confidencialidad de bases de datos en sitios WordPress operados por empresas en México y Latinoamérica. El riesgo es alta en entornos con múltiples usuarios o redes corporativas.