Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 36 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87786] The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at che…
The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-88792] The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in…
The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.
M Alto vulnerabilidad
17/09/2026
[CVE-2025-15697] The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in …
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85130] The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a p…
The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitrary JavaScript in the session of an administrator who interacts with the logged entry. Only multisite installations are affected.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63671] MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. …
MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and unsafeLinkPrefix to remove executable URLs from untrusted Markdown. validateProp checks only attributes named href or src, allowing an SVG xlink:href value repres…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92134] Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results…
Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92135] Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID w…
Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92136] Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-C…
Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-78252] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-18595] The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJ…
The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55690] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and variou…
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown service name into exception text, and includes/EmbedVideo.php returns that text a…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55691] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and variou…
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to sprintf while constructing a figure element. A quote in the class value can termina…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55692] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and variou…
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON returned through includes/EmbedService/AbstractEmbedService.php into the data-mw-i…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90650] The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The pr…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54087] EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, Fi…
EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline same-origin rendering without a download attribute or Content-Disposition attachment header. When uploads are stored under the public web root, an attacker with acc…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90943] parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in com…
parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including administrators, enabling session token theft and unauthorized actions.
M Alto vulnerabilidad
14/09/2026
[CVE-2023-28148] A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad XSS alta en Amundsen frontend 4.3.0 permite ejecución de código en navegadores
Amundsen frontend hasta versión 4.3.0 renderiza descripciones de tablas, dashboards y características sin sanitizar HTML en componentes ResourceListItem, permitiendo inyección de código malicioso a través del servicio de metadatos o Elasticsearch. Atacantes pueden ejecutar JavaScript en el navegador de todos los usuarios que visualicen resultados de búsqueda, comprometiendo sesiones y datos sensibles en plataformas de datos corporativas.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad XMS almacenado alta en Strapi 4.x y 5.x afecta gestión de contenidos
Strapi versiones 4.x hasta 4.26.2 y 5.x anteriores a 5.48.1 contienen una vulnerabilidad de cross-site scripting (XSS) almacenado en el componente de vista previa WYSIWYG del gestor de contenidos. Un usuario con rol de Author puede inyectar etiquetas script maliciosas en campos de texto enriquecido que se ejecutan en sesiones de Editor o Super Admin, permitiendo compromiso de cuentas administrativas y acceso no autorizado a sistemas de gestión de contenidos en empresas de LATAM.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87888] The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST rout…
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.