Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102831] JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jup…
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is act…
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en GitLab CE/EE permite ejecución de JavaScript malicioso (CVE-2026-84739)
GitLab ha remediado una vulnerabilidad de puntuación CVSS 8.7 que afecta versiones 13.11 a 19.4.1 en Community Edition y Enterprise Edition. Un usuario autenticado podría ejecutar código JavaScript arbitrario en la sesión del navegador de otro usuario mediante sanitización deficiente en el visor de diferencias de solicitudes de fusión. Esta vulnerabilidad de escalada de privilegios impacta directamente sistemas DevOps y repositorios de código fuente en infraestructuras altas de empresas mexicanas y latinoamericanas.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en HPE OneView permite secuestro remoto de sesiones
HPE OneView contiene una vulnerabilidad de severidad alta (CVSS 8.2) que permite a atacantes remotos secuestrar sesiones activas y ejecutar acciones no autorizadas en infraestructuras de centros de datos. Esta exposición afecta directamente a empresas en México y LATAM que utilizan HPE OneView para gestión de servidores físicos en entornos altas, representando riesgo de acceso administrativo no autorizado a recursos de TI sensibles.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en HPE OneView permite secuestro de sesiones y robo de datos (CVE-2026-76719)
HPE OneView presenta una vulnerabilidad remota (CVSS 8.2) que permite a atacantes secuestrar sesiones, acceder a datos sensibles y ejecutar acciones no autorizadas en infraestructuras de centros de datos. En LATAM, esto afecta principalmente a empresas medianas y grandes con plataformas de gestión hiperconvergente. El riesgo es alta para operaciones de TI que dependen de HPE OneView para administrar servidores, almacenamiento y virtualización.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96326] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-88804] An unauthenticated update of public UI settings could be used by remote attackers to execute a store…
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-86609] The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted throu…
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin befor…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100720] Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowe…
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits s…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100673] The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render s…
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor wh…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100641] SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it int…
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as becomes an executable event-handler attribute. Because the SiYua…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100643] SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea …
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100645] SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery an…
SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100639] SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (…
SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing a Kramdown inline attribute list (IAL). Because the shared Lute renderer parses Kramdown IAL from text/plain input, an attacker-supplied Markdown snippet…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-84095] The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one …
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-84096] The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the …
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-85081] The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File M…
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary J…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-16591] The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category…
The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affect…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93641] An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z…
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93642] An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z…
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93647] An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. …
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.