Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,971
Total alertas
3188
Críticas
10511
Altas
8
Ransomware
1057
Esta semana
RSS
M Alto vulnerabilidad
24/06/2026
[CVE-2026-9179] The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter…
The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from $_GET['order'] into $shorting) and the lack of sufficient preparation on the existing SQL query in the listPost() functi…
M Alto vulnerabilidad
24/06/2026
[CVE-2026-8705] The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` …
The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions up to, and including, 3.4.2. The handler is registered for unauthenticated users (`wp_ajax_nopriv_clearsale_total_push`), and although a `wp_verify_nonce()` check exists, the failing branch's `die()` is commented out so executi…
M Alto vulnerabilidad
24/06/2026
[CVE-2026-4297] The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in al…
The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOption() function, which is exposed via the nc.setOption XML-RPC method. The function authenticates the user via $wp_xmlrpc_server->login() (verifying credentials are valid) but does not perform any authori…
M Alto vulnerabilidad
24/06/2026
[CVE-2026-12095] The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up…
The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The script echoes internal API response d…
M Alto vulnerabilidad
24/06/2026
[CVE-2026-12100] The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up…
The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12416] The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in a…
The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parame…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12417] The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Re…
The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/06/2026
[CVE-2026-10091] The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…
The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi…
M Alto vulnerabilidad
24/06/2026
[CVE-2026-10092] The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…
The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all versions up to, and including, 1.163 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. …
M Alto vulnerabilidad
24/06/2026
[CVE-2026-10735] Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress pl…
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code throug…
M Alto vulnerabilidad
24/06/2026
[CVE-2026-10749] The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during po…
The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's double-serialization protection, allowing users with Contributor-level access and above to inject a PHP Object.
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12850] Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVisio…
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12851] Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVisio…
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12486] Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVisio…
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12846] GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled ove…
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a po…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12847] GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled ove…
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a po…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12848] GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled ove…
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a po…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12849] Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVisio…
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12485] GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled ove…
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a po…
M Alto vulnerabilidad
24/06/2026
[CVE-2026-3652] The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parame…
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator views the "P…