Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-81295] Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.
Unauthenticated Cross Site Scripting (XSS) in Under Construction
M Alto vulnerabilidad
03/09/2026
[CVE-2026-81300] Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7
M Alto vulnerabilidad
03/09/2026
[CVE-2026-81773] Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions…
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension
M Alto vulnerabilidad
03/09/2026
[CVE-2026-81776] Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84665] Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard lin…
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84673] Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's …
Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84648] In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log rec…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-76759] Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-76782] Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
M Alto vulnerabilidad
02/09/2026
XSS no autenticado en Interactive Geo Maps versiones ≤ 1.6.30 (CVSS 7.1)
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) no autenticado en Interactive Geo Maps que afecta versiones anteriores a 1.6.31. Un atacante remoto puede inyectar código malicioso que se ejecute en los navegadores de usuarios finales, comprometiendo sesiones y robando datos sensibles. Esta vulnerabilidad representa riesgo alta para portales web y aplicaciones geoespaciales desplegadas en México y Latinoamérica que utilizan este complemento.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad XSS sin autenticación en TrustedSite versiones ≤ 1.2.5
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en TrustedSite versiones 1.2.5 y anteriores, con puntuación CVSS 7.1. Un atacante remoto podría inyectar código malicioso que se ejecute en navegadores de usuarios legítimos, comprometiendo credenciales y sesiones. Afecta principalmente a empresas en LATAM que utilizan este complemento para validación de confianza en sitios web.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad XSS sin autenticación en Estatik versiones ≤4.3.4 (CVSS 7.1)
Se ha identificado una vulnerabilidad de Cross-Site Scripting (XSS) sin autenticación en Estatik versiones 4.3.4 y anteriores, que permite a atacantes inyectar código malicioso en aplicaciones web expuestas. Esta vulnerabilidad afecta principalmente a organizaciones en LATAM que utilizan este generador de sitios estáticos en entornos de producción sin restricciones de acceso. El riesgo es elevado si la aplicación procesa entrada de usuarios o está accesible desde internet.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81288] Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versi…
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81289] Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar …
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar
M Alto vulnerabilidad
02/09/2026
[CVE-2026-75528] The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Commen…
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation req…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-82883] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81737] The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by u…
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81807] The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before r…
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-77792] The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field val…
The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19723] The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properl…
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPr…