Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-19056] The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter be…
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-18937] The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accep…
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-18776] The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of i…
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-18031] The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before est…
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-18051] The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it use…
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can stri…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-17565] The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied …
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16616] The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-mov…
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16617] The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's …
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16950] The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a paramet…
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-14861] The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request …
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16570] The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of t…
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-14334] The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly s…
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-13174] The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting …
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-12983] The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in…
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-13169] The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allo…
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-11565] The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in seve…
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to …
? Crítico alerta
Hace 6 días
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2026-64849.
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad de autorización incorrecta en acmailer permite escalación de privilegios
Existe una vulnerabilidad de autorización deficiente en acmailer (CVSS 8.8) que permite a usuarios crear subcuentas con privilegios administrativos no autorizados. Esta falla afecta directamente la integridad del control de acceso en sistemas de correo empresarial. En LATAM, donde muchas organizaciones dependen de acmailer para gestión de comunicaciones altas, un atacante interno podría comprometer la infraestructura de correo y acceder a información sensible.
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad alta en plugin Atarim para WordPress permite eliminación arbitraria de archivos
El plugin Atarim para WordPress (versiones hasta 5.1.1) contiene una falla de validación de rutas de archivo que permite a atacantes autenticados con nivel de autor eliminar archivos arbitrarios del servidor. Afecta principalmente a agencias digitales y estudios de diseño en LATAM que utilizan este plugin para gestión de contenido y feedback de clientes. La vulnerabilidad requiere acceso autenticado pero representa riesgo alta en entornos multiusuario.
M Alto vulnerabilidad
Hace 6 días
Inyección SQL alta en SourceCodester Simple Online Food Ordering System 1.0
Se identificó una vulnerabilidad de inyección SQL en el módulo de administración (/admin/ajax.php?action=delete_menu) del sistema de pedidos en línea SourceCodester versión 1.0. Un atacante remoto puede manipular el parámetro ID para ejecutar comandos SQL arbitrarios, comprometiendo la integridad y confidencialidad de bases de datos de restaurantes y datos de clientes. El exploit está públicamente disponible y afecta directamente a plataformas de delivery y comercio electrónico en LATAM.