Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-94503] Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Uploa…
Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-85097] The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versi…
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a …
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-17609] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the t…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39770] Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
Unauthenticated Arbitrary File Upload in Doctreat
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39755] Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
Subscriber Arbitrary File Upload in WP Duplicate
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39757] Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
Subscriber Arbitrary File Upload in Taskbot
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39759] Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
Employer / Sales Representative Arbitrary File Upload in Workreap Core

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-32579] Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress
M Crítico vulnerabilidad
Hace 6 días
[CVE-2023-54405] H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an un…
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token pa…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-56660] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to b…