Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1815
Esta semana
RSS
M Alto vulnerabilidad
01/08/2026
Vulnerabilidades altas de bypass de autenticación en @better-auth/sso anteriores a v1.6.21
Las versiones de @better-auth/sso anteriores a 1.6.21 contienen múltiples vulnerabilidades que permiten a atacantes eludir mecanismos de autenticación SSO y acceder como usuarios arbitrarios. Los vectores incluyen fallas en validación de dominios, cuentas huérfanas de proveedores, aserciones SAML sin vinculación y XSS reflejado en endpoints de cierre de sesión, exponiendo sistemas de autenticación centralizada en empresas de LATAM que utilizan este componente en plataformas cloud o híbridas.
M Alto vulnerabilidad
01/08/2026
[CVE-2026-15052] The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vul…
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesse…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-18481] Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might a…
Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-13609] The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted…
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9'…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-56672] ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file}…
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and authenticated-equivalent API calls. The handler used web.FileResponse(path), so an uploaded .h…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-56670] ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.2…
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. This issue is fixed in version 0.28.0.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-66421] OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated …
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute with…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-66418] OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthent…
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive C…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-11707] IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affecte…
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18360] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18361] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-16969] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-16597] The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to S…
The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Alto vulnerabilidad
29/07/2026
[CVE-2026-16655] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin fo…
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that …
M Alto vulnerabilidad
29/07/2026
[CVE-2026-13425] The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array For…
The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by una…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/07/2026
[CVE-2026-14234] The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its A…
The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site request, resulting in stored Cross-Site Scripting.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-48060] Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Lite…
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentatio…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-13440] The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, S…
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-14870] The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not pro…
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-65441] Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP