Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,138
Total alertas
3230
Críticas
10635
Altas
8
Ransomware
1056
Esta semana
RSS
M Alto vulnerabilidad
02/07/2026
[CVE-2026-27425] Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Automotive Listings
M Alto vulnerabilidad
02/07/2026
[CVE-2026-27426] Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business
M Alto vulnerabilidad
02/07/2026
[CVE-2026-27430] Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
Unauthenticated Cross Site Scripting (XSS) in TheFox
M Alto vulnerabilidad
02/07/2026
[CVE-2026-27402] Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress
M Alto vulnerabilidad
02/07/2026
[CVE-2026-27404] Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
Unauthenticated Cross Site Scripting (XSS) in LMS
M Alto vulnerabilidad
02/07/2026
[CVE-2026-27060] Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
Contributor PHP Object Injection in ARMember Premium
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69156] Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/07/2026
[CVE-2026-11946] An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service …
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM ind…
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69094] Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Subscriber SQL Injection in Unicamp
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69133] Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
Subscriber Local File Inclusion in Tourmaster
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69134] Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 version…
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69152] Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versio…
Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69153] Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Trendy Travel
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69154] Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69155] Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/07/2026
[CVE-2025-58902] Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
Unauthenticated Local File Inclusion in Lighthouse
M Alto vulnerabilidad
02/07/2026
[CVE-2026-9834] The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is …
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp_db_exclude_table` parameter. This is due to the direct concatenation of user-supplied `$_POST['wp_db_exclude_table']` values into the `mysqldump` shell command string in the `mysqldump()` function of `includes/ad…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-13369] The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the att…
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a client-supplied saveProgress flag, bypassing all upload validation, path normalizat…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-14336] PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' …
PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as https://ci.eclipse.org@evil.host (userinfo trick) or https://ci.eclipse.org.evil.host (suffix trick) that satisfies the prefix…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-8441] The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' p…
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but does not provide SQL safety. The value is then concatenated directly into a numeri…