Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107303] JHipster is a development platform to quickly generate, develop, and deploy modern web applications …
JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled Blob data and companion ContentType values, return them through generated REST endpoints, and pass them to the generated openFile helper in generators/cl…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-104077] Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers …
Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because No…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-104078] Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 S…
Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formul…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-14990] IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnera…
IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad XSS alta en hMailServer 6.3.2-6.3.5 permite ejecución de scripts en webmail
Se ha identificado una vulnerabilidad de cross-site scripting (XSS) en el cliente webmail de Progressive Robot hMailServer que afecta versiones 6.3.2 a 6.3.5. Un atacante remoto puede enviar mensajes cifrados (S/MIME u OpenPGP) que, al ser descifrados en el navegador, ejecutan código malicioso con los permisos de sesión del usuario. Esto compromete la confidencialidad de correos y credenciales en empresas que usan este servidor de correo.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-103309] The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translatio…
The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-94662] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stored XSS. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-94670] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-95595] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS. This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad XPS almacenado en plugin OMGF para WordPress afecta versiones hasta 6.3.10
El plugin OMGF (GDPR/DSGVO Compliant, Faster Google Fonts) para WordPress contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado con CVSS 7.2 que permite a atacantes no autenticados inyectar código malicioso mediante el parámetro de búsqueda 's' en el feed de comentarios Atom. Afecta todas las versiones hasta 6.3.10. Debido a la insuficiente sanitización de entrada y escape de salida, el script inyectado se ejecuta en las páginas afectadas, poniendo en riesgo a visitantes y comprometiendo la integridad del sitio web.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-87971] The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a requ…
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-105316] The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some …
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-102173] The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t…
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `` attribute. This makes it possible for unauthentica…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101158] A missing input validation vulnerability in the Fileserver upload API allows an authenticated attack…
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101156] A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege adminis…
A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensit…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101157] A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacen…
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104073] NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allow…
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API to…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-106102] Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.…
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. A…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105862] Payload is a free and open source headless content management system. In versions before 3.90.0 and …
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105798] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-controlled group document filename that group_workspaces.html later interpolates into inline Share event handlers. The escapeGroupHtml function leaves apostrophes unchanged, while escapeHtml produces an HTM…