Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
20/08/2026
[CVE-2026-76764] A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an un…
A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76574] A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the …
A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-61518] ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id pa…
ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requests in its default configuration. A remote AP…
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-20030] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements us…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-71176] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76205] phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpo…
phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-70422] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
19/08/2026
[CVE-2026-56088] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-16019] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-73388] Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Unauthenticated SQL Injection in Nikstore Core
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-73391] Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
Unauthenticated SQL Injection in Total Donations
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-73183] Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
Unauthenticated SQL Injection in Maps Marker Pro
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-73185] Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-66668] Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
Subscriber SQL Injection in Community by PeepSo
M Alto vulnerabilidad
19/08/2026
[CVE-2026-32552] Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
Subscriber SQL Injection in YITH WooCommerce Membership Premium

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/08/2026
[CVE-2026-16950] The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a paramet…
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-12983] The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in…
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.
M Alto vulnerabilidad
19/08/2026
Inyección SQL alta en SourceCodester Simple Online Food Ordering System 1.0
Se identificó una vulnerabilidad de inyección SQL en el módulo de administración (/admin/ajax.php?action=delete_menu) del sistema de pedidos en línea SourceCodester versión 1.0. Un atacante remoto puede manipular el parámetro ID para ejecutar comandos SQL arbitrarios, comprometiendo la integridad y confidencialidad de bases de datos de restaurantes y datos de clientes. El exploit está públicamente disponible y afecta directamente a plataformas de delivery y comercio electrónico en LATAM.
M Alto vulnerabilidad
19/08/2026
Inyección SQL alta en SourceCodester Simple Online Food Ordering System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en el módulo de administración (/admin/ajax.php?action=save_menu) del sistema SourceCodester Simple Online Food Ordering System versión 1.0, permitiendo a atacantes remotos manipular consultas a base de datos mediante el parámetro ID. Esta afecta directamente a restaurantes y negocios de alimentos en LATAM que utilizan esta plataforma para gestionar menús y pedidos online. El exploit está disponible públicamente, elevando significativamente el riesgo de compromisos inmediatos.
M Alto vulnerabilidad
19/08/2026
Inyección SQL alta en SourceCodester Simple Online Food Ordering System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en SourceCodester Simple Online Food Ordering System 1.0 a través del parámetro Username en /admin/ajax.php?action=login. Un atacante remoto puede ejecutar comandos SQL maliciosos sin autenticación válida, comprometiendo bases de datos de órdenes, clientes y pagos. Esta vulnerabilidad afecta directamente a restaurantes, fondas y servicios de delivery en LATAM que utilicen este sistema de código abierto.