Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Alto vulnerabilidad
25/07/2026
[CVE-2026-10818] The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a…
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated…
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-65461] Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
Administrator Arbitrary File Upload in Really Simple CSV Importer
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-65455] Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
Administrator Arbitrary File Upload in MapSVG
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-27064] Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Editor Arbitrary File Upload in Mailster
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-14282] The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Video…
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() function hooked into WPForms' public wpforms_process_before_filter, which trusts the attacker-supplied multipart C…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16447] A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file …
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16332] A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /…
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16329] A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file …
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16330] A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function …
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could b…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16331] A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function…
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16327] A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing o…
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
20/07/2026
[CVE-2026-16324] A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is …
A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any …
M Alto vulnerabilidad
20/07/2026
[CVE-2026-53593] FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version …
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restricted_extensions`) is incomplete: it does not cover the `.pht` extension. The authenticated upload endpoint `POST /uploads/upload` (`SecureController@upload`) stores files with their original extension into the web-accessi…
M Alto vulnerabilidad
20/07/2026
[CVE-2026-63429] HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authe…
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user can upload files (PDF, DOC/DOCX, XLS/XLSX, CSV, TXT, MP4, images, etc., up to 10 MB) and receive a permanent public URL on the HeyForm domain. The endpoi…
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-48062] CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in …
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the client-provided filename extension. As a result, an uploaded file named shell.php containing GIF-like content could pass validation such as uploaded[avatar]|is_image[avatar]|mime_in[avatar,image/gif…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-36669] An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.…
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.
M Alto vulnerabilidad
17/07/2026
[CVE-2026-13352] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict C…
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the …
M Alto vulnerabilidad
15/07/2026
[CVE-2026-61457] The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass i…
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PATHINFO_EXTENSION), so a user with api.media.write permission can upload a file with a double extension such as shell.php.jpg to bypass the dangerous extensions bl…
A Crítico vulnerabilidad
14/07/2026
[CVE-2026-48356] Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that …
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised …
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15677] A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown funct…
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.