Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-13249] An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web manageme…
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updati…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-13248] An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command …
An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-93352] Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .ph…
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file tha…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96513] A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown p…
A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, a…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-88419] An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m…
An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content va…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95500] A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted …
A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95499] A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects…
A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/09/2026
[CVE-2026-36467] Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows…
Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-82187] The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extens…
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta de carga arbitraria de archivos en NivoCart hasta versión 2.4.0
NivoCart versiones 2.4.0 y anteriores contienen una vulnerabilidad de carga arbitraria de archivos en el endpoint File Manager multi() que permite a atacantes con acceso de solo lectura al back-office subir archivos PHP a directorios web accesibles (image/data/) y ejecutar código remoto. La validación de extensiones de archivo falla cuando el parámetro chunks es 2 o superior. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan este carrito de compras para e-commerce.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-81650] The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate…
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that exec…
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en Gravity Forms para WordPress (CVE-2026-84434)
El plugin Gravity Forms para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta 3.1.0.4. Un defecto en la validación de extensiones permite eludir controles de seguridad en campos ocultos de carga, exponiendo servidores a ejecución de código remoto. Afecta principalmente a empresas, agencias digitales y e-commerce en LATAM que dependen de formularios de contacto y recopilación de datos en WordPress.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93031] The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordP…
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported f…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-77929] ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users…
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist …
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-45140] Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unau…
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92980] HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authen…
HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-87796] The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in …
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution poss…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87935] The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to…
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-78088] The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is…
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files wh…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81236] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.