Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-15667] The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPres…
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execut…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-11613] The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up t…
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensit…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78562] The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, a…
The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78566] The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc…
The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78478] The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ…
The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “sa…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-32560] Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Gen…
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator
M Alto vulnerabilidad
24/08/2026
Inclusión de archivos local sin autenticación en Måne <= 1.7 (CVE-2026-66670)
Se identificó una vulnerabilidad de inclusión de archivos local (LFI) sin autenticación en Måne versión 1.7 y anteriores, con CVSS 8.1. Un atacante remoto podría acceder a archivos sensibles del sistema sin credenciales. Afecta principalmente a organizaciones en LATAM que ejecuten esta aplicación en entornos accesibles por red.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/08/2026
Vulnerabilidad alta de Inclusión de Archivos Local sin autenticación en Verdure Core <= 1.2
Se ha identificado una vulnerabilidad de Inclusión de Archivos Local (LFI) sin autenticación en Verdure Core versiones 1.2 y anteriores (CVSS 8.1). Esta falla permite a atacantes acceder a archivos sensibles del servidor sin necesidad de credenciales, comprometiendo datos confidenciales y configuraciones altas. Empresas en LATAM que utilizan esta plataforma en producción están expuestas a exposición de información y potencial ejecución remota de código.
M Crítico vulnerabilidad
24/08/2026
Vulnerabilidad crítica de inclusión de archivos en WP Cafe Pro < 3.0.15
Se ha identificado una vulnerabilidad de inclusión local de archivos (LFI) sin autenticación en WP Cafe Pro versiones anteriores a 3.0.15, con puntuación CVSS 9.8. Esta falla permite a atacantes remotos acceder a archivos sensibles del servidor, incluyendo configuraciones con credenciales de bases de datos. Afecta principalmente a tiendas en línea y sitios de comercio electrónico que utilizan este plugin en WordPress.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-28151] Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-28152] Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-28150] Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
M Alto vulnerabilidad
20/08/2026
[CVE-2025-15637] Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
Unauthenticated Local File Inclusion in Shuffle
M Alto vulnerabilidad
20/08/2026
[CVE-2026-75963] The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up t…
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to …
M Alto vulnerabilidad
19/08/2026
[CVE-2026-73387] Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
Unauthenticated Local File Inclusion in Resido

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73400] Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress
M Alto vulnerabilidad
18/08/2026
[CVE-2026-32464] Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
Unauthenticated Local File Inclusion in Theme Test Drive
M Alto vulnerabilidad
18/08/2026
[CVE-2026-28570] Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
Unauthenticated Local File Inclusion in Vavo Core
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66656] Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
Unauthenticated Local File Inclusion in Foton Core
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66657] Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
Unauthenticated Local File Inclusion in Biagiotti Core