Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 42 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-32575] Unauthenticated Cross Site Scripting (XSS) in SUMO Affiliates Pro <= 11.7.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SUMO Affiliates Pro
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-32577] Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-32569] Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Media folder
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-32570] Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versi…
Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-32572] Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.
Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105061] Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Mailster
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104670] Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in LearnPress

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104672] Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104814] Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Block
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104394] Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Charitable
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104395] Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
Unauthenticated Cross Site Scripting (XSS) in picu
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103346] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39760] Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-75962] The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP…
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105679] Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content…
Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file extension. This could be used to host scripts on…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105651] Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark car…
Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in versi…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105649] Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG…
Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105650] Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attac…
Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105643] Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the G…
Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-100515] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30.