Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 16169 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-93775] The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is trigger…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-83526] The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a…
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player cre…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-87780] The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted…
The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it.
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-87781] The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter befo…
The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-14335] The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is …
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user …
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-104899] The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPre…
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. Thi…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-104752] The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file up…
The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-103889] The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execut…
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template w…
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-104021] The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to,…
The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before in…
M Crítico vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-94589] The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for Word…
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload…
M Crítico vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-107645] The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, …
The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_cu…
M Crítico vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-104732] The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions …
The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compoun…
M Crítico vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-108474] In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of sever…
In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-92705] Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loa…
Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or their authors. An attacker can distribute a crafted `ASS` file together with a referenced malicious Automation script, and opening the `AS`  file execute…
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-57458] Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token…
Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at `POST /api/v1/oauth/token` for a normal bearer JSON Web Token (JWT) and refresh token. The resulting credentials are not restricted by the original API t…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-62376] Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store passwo…
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing …
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-108259] Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values f…
Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string literals in packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts. A crafted Git-valid branch name c…
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-108260] Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/…
Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link using a script-capable scheme, and a visitor who clicks the rendered link executes attacker-controlled script in the site's …
M Crítico vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-108261] Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /…
Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the Graph…
M Crítico vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-108263] Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the…
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the docu…