Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
02/09/2026
[CVE-2026-76782] Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica de XSS almacenado en SiYuan anterior a v3.8.2 permite robo de tokens API
SiYuan versiones anteriores a v3.8.2 contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el servidor de activos debido a una lista de bloqueo de extensiones incompleta. Atacantes pueden cargar archivos con extensiones como .xht, .ehtml, .xsl, .xbl o .rdf que se resuelven como tipos de medios ejecutables, permitiendo ejecutar JavaScript para robar tokens API y comprometer espacios de trabajo. El CVSS de 9.0 indica severidad crítica con alto impacto en confidencialidad e integridad.
M Alto vulnerabilidad
02/09/2026
XSS no autenticado en Interactive Geo Maps versiones ≤ 1.6.30 (CVSS 7.1)
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) no autenticado en Interactive Geo Maps que afecta versiones anteriores a 1.6.31. Un atacante remoto puede inyectar código malicioso que se ejecute en los navegadores de usuarios finales, comprometiendo sesiones y robando datos sensibles. Esta vulnerabilidad representa riesgo alta para portales web y aplicaciones geoespaciales desplegadas en México y Latinoamérica que utilizan este complemento.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad XSS sin autenticación en TrustedSite versiones ≤ 1.2.5
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en TrustedSite versiones 1.2.5 y anteriores, con puntuación CVSS 7.1. Un atacante remoto podría inyectar código malicioso que se ejecute en navegadores de usuarios legítimos, comprometiendo credenciales y sesiones. Afecta principalmente a empresas en LATAM que utilizan este complemento para validación de confianza en sitios web.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad XSS sin autenticación en Estatik versiones ≤4.3.4 (CVSS 7.1)
Se ha identificado una vulnerabilidad de Cross-Site Scripting (XSS) sin autenticación en Estatik versiones 4.3.4 y anteriores, que permite a atacantes inyectar código malicioso en aplicaciones web expuestas. Esta vulnerabilidad afecta principalmente a organizaciones en LATAM que utilizan este generador de sitios estáticos en entornos de producción sin restricciones de acceso. El riesgo es elevado si la aplicación procesa entrada de usuarios o está accesible desde internet.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81288] Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versi…
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81289] Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar …
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-75528] The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Commen…
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation req…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-82883] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81737] The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by u…
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81807] The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before r…
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-77792] The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field val…
The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19723] The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properl…
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPr…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-12865] The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters be…
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in administrator (or, for the first sink, a contributor), executes arbitrary JavaScrip…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84695] BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload …
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84370] SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG …
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, incompletely filters executable links in plugins/removeScripts.js and lib/svgo/tools.js. The plugin does not recognize namespace-prefixed SVG anchor eleme…
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad de XSS almacenado en LibreNMS 26.4.0 mediante integración Oxidized
LibreNMS versiones hasta 26.4.0 procesa sin sanitización campos JSON (nombre, IP, modelo, autor, mensaje de commit) desde la URL de integración Oxidized configurable por administrador, permitiendo inyección de XSS persistente. Un atacante que controle el servidor Oxidized puede ejecutar scripts maliciosos en el navegador de usuarios que accedan a la página de configuración de dispositivos. Esta vulnerabilidad afecta directamente a proveedores de servicios de red y administradores de infraestructura en LATAM que usan LibreNMS con Oxidized integrado.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad XSS almacenado alta en LibreNMS anterior a 26.3.1
LibreNMS versiones anteriores a 26.3.1 presentan una vulnerabilidad de cross-site scripting (XSS) almacenado en plantillas PHP legadas que procesan datos de SNMP y syslog sin validación. Un atacante que controle dispositivos de red monitoreados puede inyectar código JavaScript malicioso a través de descripciones de interfaces SNMP o campos de programas syslog, ejecutándose cuando usuarios autenticados acceden a las páginas afectadas. Esto afecta principalmente a empresas de telecom, ISPs y centros de datos en LATAM que utilizan LibreNMS para monitoreo de infraestructura.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19914] The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cu…
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected paylo…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19573] The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.