Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-18147] A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scrip…
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated…
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad XSS almacenado en SiYuan anterior a v3.8.2 afecta búsqueda de activos
SiYuan versiones anteriores a v3.8.2 contienen una vulnerabilidad de cross-site scripting (XSS) almacenado en la función de búsqueda de activos. Atacantes autenticados pueden inyectar código malicioso en nombres de archivos que se ejecuta en el navegador de usuarios legítimos, permitiendo manipulación de estado de aplicación y ejecución de solicitudes API no autorizadas. El riesgo es moderado-alto en entornos colaborativos donde múltiples usuarios acceden a repositorios compartidos.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad XSS almacenado alta en SiYuan anterior a v3.8.2 afecta vista previa de activos
SiYuan antes de la versión 3.8.2 contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en la función de vista previa de activos de búsqueda. Los atacantes pueden insertar contenido malicioso en activos de texto dentro de espacios de trabajo para ejecutar código JavaScript con privilegios autenticados. Esto permite acceso no autorizado a APIs internas y manipulación de datos en la instancia SiYuan, representando riesgo significativo para organizaciones que almacenan información sensible en esta plataforma de gestión de conocimiento.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad de XSS en SiYuan anterior a v3.8.2 permite ejecución de código JavaScript
SiYuan versiones anteriores a v3.8.2 no codifica correctamente las rutas de plantillas de cuadernos persistidas en atributos HTML, permitiendo ataques de cross-site scripting (XSS). Un atacante puede crear rutas de plantilla maliciosas que se ejecutan cuando un usuario abre la configuración del cuaderno, comprometiendo datos sensibles y manipulando el estado de la aplicación mediante solicitudes API del mismo origen. Afecta principalmente a organizaciones que utilizan SiYuan para gestión de notas y documentación en entornos colaborativos.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-14989] The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored…
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpl_user_preference' parameter in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user access…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-83593] The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulner…
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-84293] The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Script…
The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected p…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-13359] The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress …
The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84942] Improper input validation in the Vega expression function implementation in OpenSearch Dashboards al…
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function pro…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75993] ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could ex…
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69417] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69402] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86738] Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to …
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en SiYuan anterior a 3.8.2 permite ejecución de código remoto
SiYuan versiones anteriores a 3.8.2 presentan una vulnerabilidad de ejecución de código remoto (CVSS 8.8) que permite a atacantes ejecutar scripts maliciosos con acceso completo a Node.js cuando usuarios pegan contenido desde el portapapeles. La falla radica en que la aplicación no valida el tipo MIME personalizado text/siyuan antes de procesar datos pegados en el renderizador Electron. Empresas en LATAM que utilizan SiYuan como herramienta de gestión de conocimiento o notas en equipos de desarrollo están expuestas a compromiso completo del sistema operativo.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81798] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84817] Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84818] Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
Unauthenticated Cross Site Scripting (XSS) in Open User Map
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84820] Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons…
Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86431] league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scrip…
league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\x0Conclick="alert(1)"}) bypasses the AttributesHelper::filterAttributes() 'on*' event-handler filter because PHP's trim() does not strip U+000C, causing the attribute to be written …
M Alto vulnerabilidad
07/09/2026
[CVE-2026-6431] The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugi…
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts …