Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
Buscando: "Multiple Vendors" — 8785 resultados ✕ Limpiar búsqueda
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1061
Esta semana
RSS
M Alto vulnerabilidad
11/07/2026
[CVE-2025-6784] The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, a…
The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the plugin. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
M Alto vulnerabilidad
11/07/2026
[CVE-2026-7655] The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in vers…
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, …
M Alto vulnerabilidad
11/07/2026
[CVE-2026-13378] The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site …
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
11/07/2026
[CVE-2026-3576] The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forge…
The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. The send_http_post() function validates the host of the provided URL against an allowlist that inclu…
M Alto vulnerabilidad
11/07/2026
[CVE-2026-2354] The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed…
The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's `wp_check_filetype_and_ext` filter and uses `strpos()` to check if a filename contains a configured extension string, ra…
M Alto vulnerabilidad
11/07/2026
[CVE-2026-14262] The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable t…
The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving …
M Alto vulnerabilidad
11/07/2026
[CVE-2026-15335] The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Par…
The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/07/2026
[CVE-2026-15338] The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion i…
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be us…
M Alto vulnerabilidad
11/07/2026
[CVE-2026-13114] The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Store…
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u…
M Alto vulnerabilidad
11/07/2026
[CVE-2026-13353] The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress i…
The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and StartImport, combined with the plugin nonce being exposed to any authenticated us…
M Alto vulnerabilidad
11/07/2026
[CVE-2026-13756] The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to…
The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator b…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-42952] Previously, there was no throttling on repeated authentication attempts to the charging station bac…
Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-44383] Multiple connections to the backend using the same charging station ID are allowed, which could all…
Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-14480] OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web U…
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database field and later uses this value as the destination path for an uploaded file without validating or restricting the path. Because Python os.path.join() honors attac…
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-15089] vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest regis…
vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-20744] The charging station websocket endpoint accepts connections without proper authentication, which co…
The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-11913] vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-49213] TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/…
TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the IPv6 unspecified address :: because validateIPAddress blocks local, metadata, and private ranges but does not block :: or its expanded form. A workspace editor or creator can configure a server-side HTTP Request block or guarded script fetch to…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-13244] Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup…
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-15081] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.