Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-58409] ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated admin…
ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a malicious plugin ZIP archive containing a PHP webshell. The application explicitly includes 'php' in its ALLOWED_EXTENSIONS list, while the dangerous extensions denylist (DENIED_EXTENSIONS) fails to block standard .php fi…
M Alto vulnerabilidad
13/07/2026
[CVE-2026-49972] Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attac…
Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised within a double extension such as shell.php.jpg. The PATHINFO_FILENAME extraction preserves the inner .php extension in the base name, and on misconfigured Apache or nginx servers that execute any file…
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57710] Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbo…
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57719] Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-…
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through
M Alto vulnerabilidad
12/07/2026
[CVE-2026-15488] A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileCon…
A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.4 is able to address this issu…
P Alto vulnerabilidad
11/07/2026
[CVE-2026-57828] Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla ex…
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
R Crítico vulnerabilidad
11/07/2026
[CVE-2026-57827] Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The J…
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/07/2026
[CVE-2026-2354] The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed…
The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's `wp_check_filetype_and_ext` filter and uses `strpos()` to check if a filename contains a configured extension string, ra…
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-15282] The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing …
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-13430] The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all…
The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass, where the extension allow-list check in ajax_import_media_start() uses pathinfo() on the raw ZIP entry name (e.g., 'shell.…
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-14894] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Uplo…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separat…
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-15158] The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up…
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extens…
M Crítico vulnerabilidad
08/07/2026
[CVE-2026-58480] Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file …
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension file…
M Alto vulnerabilidad
08/07/2026
[CVE-2026-14489] The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty…
The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
M Alto vulnerabilidad
08/07/2026
[CVE-2026-14158] The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions …
The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the widget-logic-update-conditional-tags AJAX action combined with insufficient sanitization of the 'nwlv[cod-tag]' parameter before storage and subsequ…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/07/2026
[CVE-2026-23698] Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin …
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manife…
M Alto vulnerabilidad
07/07/2026
[CVE-2026-23697] Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileg…
Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible s…
M Crítico vulnerabilidad
07/07/2026
[CVE-2026-14345] The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress…
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_sho…
E Crítico vulnerabilidad
06/07/2026
[CVE-2026-9182] Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker c…
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Ent…
A Crítico vulnerabilidad
06/07/2026
[CVE-2026-24014] Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trig…
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file writ…