Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-3418] The System REST API accepts user-supplied file uploads without enforcing sufficient validation on th…
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Dependin…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-66665] Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Arbitrary File Upload in Type Hub
M Crítico vulnerabilidad
04/08/2026
Vulnerabilidad crítica de carga de archivos peligrosos en HUMANIST Digital Human Resources
HUMANIST Digital Human Resources (versiones 26.0 a 26.0.x) contiene una vulnerabilidad de carga sin restricciones que permite a atacantes subir shells web al servidor. Esta falla afecta directamente a departamentos de Recursos Humanos en México y LATAM que gestionen nómina y datos sensibles de empleados. El CVSS 9.8 indica riesgo crítico de compromiso total del sistema.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-16618] The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking …
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-14483] The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary Fi…
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installation…
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-63223] CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload valid…
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads u…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-16610] The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Executio…
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-63227] An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module desig…
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13714] The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate th…
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve rem…
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-65461] Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
Administrator Arbitrary File Upload in Really Simple CSV Importer
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-65455] Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
Administrator Arbitrary File Upload in MapSVG
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-27064] Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Editor Arbitrary File Upload in Mailster
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-14282] The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Video…
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() function hooked into WPForms' public wpforms_process_before_filter, which trusts the attacker-supplied multipart C…
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-48062] CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in …
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the client-provided filename extension. As a result, an uploaded file named shell.php containing GIF-like content could pass validation such as uploaded[avatar]|is_image[avatar]|mime_in[avatar,image/gif…
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-36669] An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.…
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Crítico vulnerabilidad
14/07/2026
[CVE-2026-48356] Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that …
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised …
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-58409] ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated admin…
ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a malicious plugin ZIP archive containing a PHP webshell. The application explicitly includes 'php' in its ALLOWED_EXTENSIONS list, while the dangerous extensions denylist (DENIED_EXTENSIONS) fails to block standard .php fi…
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57710] Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbo…
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57719] Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-…
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through
R Crítico vulnerabilidad
11/07/2026
[CVE-2026-57827] Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The J…
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.