Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Ni" — 2104 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1212
Esta semana
RSS
M Alto vulnerabilidad
20/09/2026
[CVE-2026-82842] The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for …
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administ…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87067] The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instan…
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-81650] The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate…
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that exec…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-93962] A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element …
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Up…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-93959] A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue a…
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-93958] A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function syst…
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-94056] Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers…
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
19/09/2026
[CVE-2026-93990] Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allo…
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-93992] Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allow…
Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-93993] Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation p…
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de inyección de comandos en Totolik A3002MU
Se ha identificado una debilidad en el enrutador Totolik A3002MU versión Hh-B20211125.1046 que permite inyección de comandos remotos a través del parámetro localPin en la función formWsc del archivo /boafrm/formWsc. La vulnerabilidad tiene puntuación CVSS 9.9 (crítica) y ya cuenta con exploits públicamente disponibles, exponiendo a empresas en LATAM que utilizan este dispositivo a acceso no autorizado e infiltración de redes.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución de shortcodes en ProfilePress para WordPress
El plugin ProfilePress para WordPress (versiones hasta 4.17.2) es vulnerable a ejecución arbitraria de shortcodes por usuarios autenticados debido a validación insuficiente antes de ejecutar do_shortcode. Esta vulnerabilidad afecta sitios de e-commerce, formularios de registro y portales de contenido restringido ampliamente utilizados en LATAM. Un atacante autenticado podría inyectar código malicioso que se ejecute en el contexto del sitio WordPress.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad XLS almacenado en plugin Quill Forms para WordPress (CVE-2026-15664)
El plugin Quill Forms versiones hasta 5.7.1 es vulnerable a inyección de scripts maliciosos (XLS) a través del campo 'Other' en formularios de opción múltiple, afectando sitios WordPress sin autenticación requerida. Atacantes pueden ejecutar código JavaScript arbitrario en navegadores de usuarios visitantes, comprometiendo datos sensibles en formularios de encuestas y cuestionarios. Impacta principalmente a sitios de comercio electrónico, educación y servicios financieros en LATAM que utilizan este plugin para recolectar información de clientes.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-86814] The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirm…
The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-88824] The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST rout…
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/09/2026
[CVE-2026-88926] The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise a…
The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-76554] The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an im…
The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts…
M Alto vulnerabilidad
19/09/2026
[CVE-2026-76790] The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several va…
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-85680] The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user suppli…
The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en router Totolink A3002MU
Se ha descubierto una falla de seguridad crítica (CVSS 10.0) en el router Totolik A3002MU versión Hh-B20211125.1046 que permite desbordamiento de búfer remoto a través del parámetro submit-url en la función formWlWds. El exploit está disponible públicamente, aumentando significativamente el riesgo de compromiso en infraestructuras de pequeñas y medianas empresas en Latinoamérica que utilizan este dispositivo como gateway de red.