Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103474] yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, a…
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad alta de carga de archivos arbitrarios en EasyFlow .NET de Digiwin
EasyFlow .NET desarrollado por Digiwin contiene una vulnerabilidad de carga arbitraria de archivos (CVSS 7.2) que permite a atacantes remotos privilegiados ejecutar web shells y código malicioso en servidores. Esta vulnerabilidad afecta directamente a organizaciones en México y LATAM que utilizan esta plataforma para flujos de trabajo empresariales, comprometiendo la integridad y confidencialidad de datos altas.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta de inyección en Zohocorp ManageEngine DDI Central 6.2.0
ManageEngine DDI Central versiones 6.2.0 con build inferior a 6201 contiene una vulnerabilidad de inyección de configuración en Keepalived que permite a operadores autenticados modificar la configuración de alta disponibilidad. Un usuario con rol de operador podría ejecutar comandos con privilegios root en el servidor DDI Central, comprometiendo la integridad de infraestructuras altas de DNS y DHCP en empresas latinoamericanas.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta de carga de archivos en eBA Plus permite inyección de web shells
eBA Plus Document and Workflow Management System (versiones 6.7.141 a 10.0.10) contiene una vulnerabilidad de carga sin restricciones que permite a atacantes subir archivos ejecutables y comprometer servidores web. Este sistema es utilizado por organismos públicos y empresas en México y LATAM para gestión documental; su explotación puede resultar en acceso no autorizado y control total del servidor.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-100389] GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP conne…
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-13248] An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command …
An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96513] A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown p…
A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-88419] An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m…
An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content va…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95500] A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted …
A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95499] A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects…
A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-36467] Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows…
Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta de carga arbitraria de archivos en NivoCart hasta versión 2.4.0
NivoCart versiones 2.4.0 y anteriores contienen una vulnerabilidad de carga arbitraria de archivos en el endpoint File Manager multi() que permite a atacantes con acceso de solo lectura al back-office subir archivos PHP a directorios web accesibles (image/data/) y ejecutar código remoto. La validación de extensiones de archivo falla cuando el parámetro chunks es 2 o superior. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan este carrito de compras para e-commerce.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-81650] The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate…
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that exec…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93031] The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordP…
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported f…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-77929] ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users…
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92980] HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authen…
HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87935] The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to…
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-78088] The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is…
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files wh…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81236] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81239] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.