Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1780
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en código de volcado de núcleo ELF permite escritura de memoria fuera de límites
Una vulnerabilidad en el procesamiento de volcados de núcleo ELF (CVE-2026-58088, CVSS 7.4) permite que procesos no privilegiados que compartan espacio de direcciones mediante rfork(2) causen desbordamientos de búfer al mutar mapas de memoria entre dos pasadas de iteración. Afecta principalmente a sistemas Unix/Linux en servidores y estaciones de trabajo en LATAM donde se ejecutan aplicaciones con multiprocessing.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad XSS almacenado en plugin TranslatePress para WordPress hasta v3.2.5
El plugin TranslatePress para WordPress contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado sin autenticación requerida en versiones hasta 3.2.5. Los marcadores especiales '#!trpst#' y '#!trpen#' se reescriben incondicionalmente a caracteres HTML, permitiendo inyección de código malicioso. Afecta principalmente a sitios multilingües en LATAM que utilizan este plugin para traducción de contenidos.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad XSS en WP Statistics afecta sitios WordPress hasta versión 14.16.8
El plugin WP Statistics para WordPress contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el parámetro 'utm_campaign' que permite a atacantes no autenticados inyectar scripts maliciosos. La falla afecta todas las versiones hasta 14.16.8 y se ejecuta cuando visitantes acceden a páginas comprometidas, poniendo en riesgo datos de usuarios y credenciales en sitios empresariales, de comercio electrónico y portales informativos comunes en LATAM.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-49428] Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly fr…
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-49429] The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to…
The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but used the original 64-bit size as the buffer limit when writing records. A local user with the "userused" delegated ZFS permission can trigger a kernel heap overflow via the ZFS_IOC_USERSPACE_MANY ioctl, potentially escalating privileges.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-49422] The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace…
The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the lock. After reacquiring, it verifies that the TCP stack had not been switched away, but did not reload its pointer to the stack's per-connection control block. If userspace switches stacks twice during this window, the check will succeed but the saved pointer will refer to fr…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-19842] The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML respo…
The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-49420] The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without check…
The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer, or whether the result fit back in the original packet. A host sending crafted RTSP traffic from inside a NAT gateway using libalias can overflow a stack buffer, potentially achieving remote code execution in the kernel (when using ipfw(4) NAT) or in…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-19055] The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parame…
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-19056] The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter be…
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-17565] The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied …
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-16616] The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-mov…
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-16617] The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's …
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-16950] The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a paramet…
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-14861] The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request …
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-16570] The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of t…
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-14334] The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly s…
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-13174] The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting …
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-12983] The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in…
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-13169] The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allo…
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators.