Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
[CVE-2026-91122] Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0…
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges could store the crafted placeholder in a post. When another user opened the post and clicked the vi…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-62368] Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.crea…
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session.…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-63498] Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint G…
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist use…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-56736] phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in…
phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that executes in an administrator's browser when they review or edit a user-submitted FAQ entry. This leads to admin account takeover via session theft. The vulnerability…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84683] A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of j…
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the output is expanded into an HTML anchor whose href is not scheme- filtered or esca…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95528] Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions…
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95529] Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95515] Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94176] Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94179] Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93622] Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93774] Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93526] Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets
M Alto vulnerabilidad
23/09/2026
[CVE-2026-77394] OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or mor…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /openc3-api/screen whose BUTTON widget action is evaluated by openc3-cosmos-init/plugins/packages/openc3-vue-common/src/widgets/ButtonWidget.vue in another operator's …
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta en Tauri: omisión de CSP permite ejecución arbitraria de scripts
Tauri contiene una falla en su mecanismo de Content Security Policy (CSP) que permite a atacantes ejecutar scripts arbitrarios al incluir esquemas data: o blob: en la directiva script-src, anulando la protección del nonce aleatorio. Aplicaciones Tauri en México y LATAM que procesen contenido dinámico están expuestas a inyección de código y compromiso de datos sensibles.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18131] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execut…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75744] Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability …
Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's accoun…
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad XSS almacenado alta en plugin WP Yelp Review Slider (CVE-2026-93778)
El plugin WP Yelp Review Slider para WordPress en versiones hasta 9.2 presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado que permite a atacantes no autenticados inyectar scripts maliciosos a través del texto de reseñas de Yelp importadas. La falta de sanitización de entrada y escapado de salida permite que estos scripts se ejecuten cuando usuarios acceden a páginas comprometidas, afectando potencialmente datos sensibles y sesiones de administradores en sitios WordPress de empresas en LATAM.
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad XSS almacenado en WPC Product Bundles for WooCommerce (CVE-2026-93836)
El plugin WPC Product Bundles para WooCommerce contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el parámetro 'qty' en versiones hasta 8.6.6, permitiendo a atacantes no autenticados inyectar código malicioso que se ejecuta cuando usuarios acceden a páginas comprometidas. Afecta tiendas en línea y plataformas de comercio electrónico en LATAM que utilizan WooCommerce. CVSS 7.2 (alto).
M Alto vulnerabilidad
22/09/2026
[CVE-2026-92438] The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputtin…
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission.