Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1880
Esta semana
RSS
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57769] Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Grand Photography
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57809] Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57699] Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
Subscriber Cross Site Scripting (XSS) in Slider Pro
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57701] Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57704] Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Manager
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57370] Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 ver…
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57374] Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57397] Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Coaching
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57427] Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57428] Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients
M Alto vulnerabilidad
23/07/2026
[CVE-2026-12421] The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field V…
The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-7232] The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter …
The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit chain combi…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-7534] The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scrip…
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionally granting the custom `rs_earning_read` capability to all users — including unauthenticated visitors…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-12968] The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not r…
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60664] Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Conten…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60646] Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Co…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the att…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60650] Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Co…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the att…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60634] Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Conten…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. …
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60635] Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Conten…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. …
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60636] Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Conten…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. …