Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-82832] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-91127] File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and…
File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink targets into generated HTML after character escaping but without restricting URL schemes. A crafted legacy DOC file could place javascript:, vbscript:, da…
M Alto vulnerabilidad
18/09/2026
[CVE-2025-61682] Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query dat…
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93659] Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escapi…
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad XPS almacenado en Popup Maker para WordPress afecta versiones hasta 1.24.0
El plugin Popup Maker para WordPress es vulnerable a inyección de scripts (XSS almacenado) en el parámetro values[Name] hasta la versión 1.24.0, permitiendo que atacantes sin autenticación inyecten código malicioso en páginas públicas. Esta vulnerabilidad (CVSS 7.2) afecta directamente a tiendas en línea y sitios de generación de leads en LATAM que usan este plugin para captura de datos.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad de Cross-Site Scripting Almacenado en Jeg Kit for Elementor hasta v3.2.16
El plugin Jeg Kit for Elementor para WordPress contiene una vulnerabilidad de Stored XSS (CVSS 7.2) que permite a atacantes no autenticados inyectar scripts maliciosos a través de contenido de comentarios. Los scripts se ejecutan cuando otros usuarios acceden a las páginas afectadas, comprometiendo datos de visitantes y administradores. Afecta todas las versiones hasta la 3.2.16, siendo alta en sitios de e-commerce y portales corporativos comunes en LATAM.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad XSS Almacenado en plugin Complianz GDPR/CCPA para WordPress (CVE-2026-83561)
El plugin Complianz GDPR/CCPA Cookie Consent Banner para WordPress contiene una vulnerabilidad de Cross-Site Scripting almacenado (XSS) en versiones hasta la 7.5.4. Atacantes no autenticados pueden inyectar scripts maliciosos a través del contenido de comentarios usando la expresión regular del bloqueador de cookies de Elementor. La falla resulta de validación insuficiente de entrada y escape inadecuado de salida. Empresas en México y LATAM que usen este plugin están en riesgo de comprometimiento de datos de visitantes y sesiones de usuarios.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-67103] HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could a…
HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93485] Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-88825] The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearan…
The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-85127] The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type …
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-85122] The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted va…
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-83946] Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal…
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54506] Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor…
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in system/functions.php, whose on* event-handler regular expression omits the forward-slash delimiter and whose do-while condition compares the string to itself, so forb…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-77615] Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.…
Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-76154] A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user …
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-45143] Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo…
Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue and public/main/template/default/message/view_message.html.twig. An authenticated low-privilege user, including a student, can directly address crafted message cont…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54253] TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/dow…
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(error.message) as text/html without a Content Security Policy. When a logged-in operator follows a cra…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92986] SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping marku…
SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92985] SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when render…
SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scripts in the Electron renderer with access to child_process for command execution.