Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
19/08/2026
[CVE-2026-19055] The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parame…
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-19056] The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter be…
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-16617] The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's …
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-16570] The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of t…
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-14334] The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly s…
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-52854] Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded…
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-54347] Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accept…
Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML escaping, and templates/Froxlor/table/table.html.twig renders the callback result with the raw filter. An authenticated customer …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-55839] Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Mark…
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaScript event-handler attributes through the custom [[link]] syntax, causing stored cross-site scripting when another user opens the description or information panel…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-45115] MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sa…
MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list in Private Messages pass usernames through htmlspecialchars_uni(), which may leave single quotes unescaped. The payload …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-45116] MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly…
MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injection. UserDataHandler::verify_profile_fields() only performs the specialized validation when is_array($profile_fields[$field]) is true. A non-array profile_fields[fidX] value instead of the expected prof…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73382] Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Site Reviews
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73393] Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Subscribe2
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73375] Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73378] Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73358] Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73360] Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73361] Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18…
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73362] Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in URL Shortify
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73351] Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73190] Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages