Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-94503] Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Uploa…
Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-85097] The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versi…
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a …
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-17609] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the t…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39770] Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
Unauthenticated Arbitrary File Upload in Doctreat
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39755] Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
Subscriber Arbitrary File Upload in WP Duplicate
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39757] Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
Subscriber Arbitrary File Upload in Taskbot
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39759] Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
Employer / Sales Representative Arbitrary File Upload in Workreap Core

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-32579] Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress
M Crítico vulnerabilidad
Hace 6 días
[CVE-2023-54405] H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an un…
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token pa…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-56660] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to b…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-75873] The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one o…
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-70356] The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attack…
The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-82901] The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due …
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o…
M Crítico vulnerabilidad
26/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en plugin Request a Quote for WooCommerce
El plugin Request a Quote for WooCommerce para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta la 2.9.2 debido a validación insuficiente de extensiones y tipos MIME en la función afrfq_submit_quote_via_popup(). Un atacante puede cargar archivos maliciosos (como shells PHP) directamente al servidor sin restricción, comprometiendo completamente sitios de comercio electrónico en LATAM. Con CVSS 9.8, afecta principalmente a pequeñas y medianas empresas que usan este plugin para gestionar cotizaciones de productos.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-42322] Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/…
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when constructing the stored filename. An authenticated administrator can upload image content with a server-executable final extension, causing the file to be placed…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-13249] An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web manageme…
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updati…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-93352] Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .ph…
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file tha…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-82187] The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extens…
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en Gravity Forms para WordPress (CVE-2026-84434)
El plugin Gravity Forms para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta 3.1.0.4. Un defecto en la validación de extensiones permite eludir controles de seguridad en campos ocultos de carga, exponiendo servidores a ejecución de código remoto. Afecta principalmente a empresas, agencias digitales y e-commerce en LATAM que dependen de formularios de contacto y recopilación de datos en WordPress.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-45140] Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unau…
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.