Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-108113] ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI questio…
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server u…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-108101] HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAtt…
HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code.
M Alto vulnerabilidad Nuevo
Hace 10 horas
[CVE-2025-15700] The AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted from…
The AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted from an uploaded ZIP archive during its listing-import feature, allowing users with the AWP Classifieds WordPress plugin before 4.4.9's management capability to upload arbitrary PHP files to a publicly accessible, network-shared directory and achieve remote code execution.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-91844] Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and F…
Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Using Malicious Files. This issue affects eimzamip: from v1.6.4 before v1.6.6.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-17196] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File T…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. Thi…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105862] Payload is a free and open source headless content management system. In versions before 3.90.0 and …
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104069] HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() wh…
HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it u…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105701] The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to…
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on t…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-82988] There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unkno…
There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105679] Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content…
Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file extension. This could be used to host scripts on…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105651] Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark car…
Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in versi…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105649] Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG…
Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105630] Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege work…
Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Content-Type, and the asset-download endpoint creates a presigned URL with Content-Disposition: inline. In the default self-hosted MinIO deployment, the asset …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104890] Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7…
Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP t…
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta de ejecución remota de código en W (wcms) versión 3.18.0 y anteriores
W (vincent-peugnet/wcms) versión 3.18.0 y anteriores contiene una vulnerabilidad de ejecución remota de código (RCE) que permite a editores autenticados escribir archivos arbitrarios mediante la validación insuficiente en POST /api/v0/media/upload/[*:path]. Los atacantes pueden cargar archivos PHP ejecutables, utilizar secuencias codificadas ../ para escribir fuera del directorio de medios, y eliminar archivos arbitrarios. Esta vulnerabilidad afecta principalmente a plataformas de gestión de contenidos desplegadas en servidores web de empresas mexicanas y latinoamericanas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104637] A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remo…
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de carga de archivos sin restricción en YesWiki anterior a 4.6.7
YesWiki versiones anteriores a 4.6.7 presentan una vulnerabilidad de carga de archivos no restringida que permite a administradores autenticados ejecutar código PHP malicioso en el servidor mediante la importación de CSV en Bazar. Un atacante puede importar un archivo CSV con referencias a URLs PHP remotas que se guardan sin validación de extensión y se ejecutan como código del lado del servidor, comprometiendo la integridad del sitio web y los datos alojados.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-92820] The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in al…
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102143] An unauthenticated attacker could cause a file with attacker-controlled content to be written to the…
An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102130] Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, …
Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.