Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96814] Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96816] Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.…
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94078] Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Site Reviews
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94081] Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login
M Alto vulnerabilidad
30/09/2026
[CVE-2026-93514] Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram
M Alto vulnerabilidad
30/09/2026
[CVE-2026-93770] Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Statistics
M Alto vulnerabilidad
30/09/2026
[CVE-2026-93512] Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-27371] Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Unauthenticated Cross Site Scripting (XSS) in WPFunnels
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102385] Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102395] Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102396] Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102398] Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100507] Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versio…
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad XSS almacenado alta en plugin Post Views Stats Counter para WordPress
El plugin Post Views Stats Counter de WordPress es vulnerable a inyección de scripts almacenados (Stored XSS) a través del encabezado User-Agent en versiones hasta la 1.1.7, permitiendo a atacantes no autenticados ejecutar código malicioso en páginas que afecta a todos los visitantes. Esta vulnerabilidad representa alto riesgo para sitios web de empresas, organismos públicos y plataformas de comercio electrónico en LATAM que utilicen este plugin sin actualizar.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-91832] The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings …
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-92994] The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents …
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-89193] The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTM…
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-85573] The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload typ…
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96649] The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress i…
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84409] The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP conne…
The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled …