Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-94662] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stored XSS. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-94670] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-95595] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS. This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad XPS almacenado en plugin OMGF para WordPress afecta versiones hasta 6.3.10
El plugin OMGF (GDPR/DSGVO Compliant, Faster Google Fonts) para WordPress contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado con CVSS 7.2 que permite a atacantes no autenticados inyectar código malicioso mediante el parámetro de búsqueda 's' en el feed de comentarios Atom. Afecta todas las versiones hasta 6.3.10. Debido a la insuficiente sanitización de entrada y escape de salida, el script inyectado se ejecuta en las páginas afectadas, poniendo en riesgo a visitantes y comprometiendo la integridad del sitio web.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-87971] The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a requ…
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-105316] The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some …
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-102173] The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t…
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `` attribute. This makes it possible for unauthentica…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-101158] A missing input validation vulnerability in the Fileserver upload API allows an authenticated attack…
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-101156] A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege adminis…
A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensit…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-101157] A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacen…
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-104073] NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allow…
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API to…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-106102] Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.…
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. A…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105862] Payload is a free and open source headless content management system. In versions before 3.90.0 and …
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105798] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-controlled group document filename that group_workspaces.html later interpolates into inline Share event handlers. The escapeGroupHtml function leaves apostrophes unchanged, while escapeHtml produces an HTM…
M Alto vulnerabilidad
Hace 3 días
XSS sin autenticación en Fluent Forms Pro Add On Pack <= 6.2.13
Vulnerabilidad de Cross Site Scripting (XSS) sin autenticación afecta Fluent Forms Pro Add On Pack en versiones 6.2.13 y anteriores. Atacantes pueden inyectar código malicioso en formularios web sin credenciales, comprometiendo datos de usuarios y sesiones. Esta vulnerabilidad impacta principalmente a empresas en LATAM que usan este plugin en WordPress para gestión de formularios y contacto.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
XSS no autenticado en Video Background Block (≤2.0.3) – CVSS 7.1
Vulnerabilidad de Cross-Site Scripting (XSS) sin autenticación en el plugin Video Background Block permite a atacantes inyectar código malicioso a través de la funcionalidad de video de fondo en secciones. Afecta versiones 2.0.3 y anteriores. El riesgo es alto para sitios WordPress en México y LATAM que usen este componente sin actualizar, exponiendo a robo de sesiones y datos de usuarios.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-42635] XSS sin autenticación en WooCommerce Simple Auctions <= 3.0.10
Vulnerabilidad de Cross Site Scripting (XSS) sin autenticación requerida en WooCommerce Simple Auctions afecta versiones hasta 3.0.10. Permite a atacantes inyectar código malicioso en tiendas de comercio electrónico, comprometiendo sesiones de clientes y administradores. Riesgo alta para plataformas de subastas basadas en WordPress en LATAM.
M Alto vulnerabilidad
Hace 3 días
XSS sin autenticación en WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6
Una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación afecta el plugin WP Cookie Notice en versiones hasta 4.4.6, permitiendo a atacantes inyectar código malicioso que se ejecuta en navegadores de visitantes. El riesgo es alta para sitios WordPress en México y LATAM que dependen de este plugin para cumplir normativas de privacidad (GDPR, CCPA, ePrivacy), pudiendo comprometer datos de usuarios y credibilidad organizacional.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-42418] Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Social Rocket
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-40806] Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0…
Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor