Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1739
Esta semana
RSS
M Crítico vulnerabilidad
Hace 2 días
Vulnerabilidad crítica de carga de archivos sin restricción en xShop 3.0.3 (CVE-2026-49849)
xShop, plataforma de e-commerce de código abierto basada en Laravel, contiene una vulnerabilidad de carga de archivos sin validación que permite a administradores autenticados subir y ejecutar archivos PHP, logrando ejecución remota de código (RCE) con acceso total al servidor. Afecta directamente a tiendas en línea operadas por pequeñas y medianas empresas en LATAM. La versión 3.0.4 corrige el problema.
M Crítico vulnerabilidad
Hace 3 días
Carga arbitraria de archivos en IT Residence <= 3.2.1 (CVE-2026-74014)
Vulnerabilidad crítica (CVSS 9.9) en IT Residence versiones 3.2.1 y anteriores permite a suscriptores cargar archivos arbitrarios en servidores afectados. Esta falla expone sistemas de gestión inmobiliaria, comunes en empresas de administración de propiedades y desarrolladores en México y Latinoamérica, a ejecución remota de código y compromiso total de infraestructura.
M Crítico vulnerabilidad
Hace 3 días
Carga arbitraria de archivos en Smart Cleaning ≤ 4.8.6 afecta suscriptores
Se reporta una vulnerabilidad crítica (CVSS 9.9) en Smart Cleaning versiones 4.8.6 y anteriores que permite a usuarios suscritos cargar archivos arbitrarios en servidores. Esta falla compromete la integridad de sistemas y facilita inyección de malware en infraestructuras empresariales de LATAM. Afecta especialmente a empresas que utilizan esta plataforma para gestión de servicios de limpieza en múltiples sedes.
M Crítico vulnerabilidad
Hace 3 días
Carga arbitraria de archivos en Warehouse Cargo <= 2.6.9 (CVE-2026-74018)
Warehouse Cargo en versiones 2.6.9 y anteriores contiene una vulnerabilidad crítica (CVSS 9.9) que permite a usuarios suscritos cargar archivos arbitrarios en sistemas afectados. Esta falla expone servidores en México y Latinoamérica a compromiso total de integridad de datos y ejecución de código remoto en infraestructuras logísticas y de almacenamiento.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66600] Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
Author Arbitrary File Upload in Media LIbrary Assistant
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-14946] A high privileged remote attacker can upload a .php file and then request it directly from /uploads/…
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-15049] The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a …
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-68899] Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation…
Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavailable and the validation fell back to the attacker-controlled fileObj.type supplied through server/routes/attachmentApi.js. On deployments with WITH_API=tr…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-32475] Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Usin…
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73996] Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Unauthenticated Arbitrary File Upload in Masteriyo - LMS
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-66627] Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Contributor Arbitrary File Upload in GP Premium
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-32474] Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
Contributor Arbitrary File Upload in Templatiq
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-32463] Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Contributor Arbitrary File Upload in Sync Post With Other Site
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-28192] Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-15748] The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up …
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler th…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-65640] WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file uploa…
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users…
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-50768] File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a r…
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16137] In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credential…
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-74845] Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulner…
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de carga arbitraria de archivos en plugin ProSolution WP Client para WordPress
El plugin ProSolution WP Client para WordPress (versiones hasta 2.0.10) permite a atacantes cargar archivos arbitrarios explotando validación insuficiente en la función proSol_handleFileUpload. La vulnerabilidad reside en la falta de validación del encabezado Content-Disposition, que puede sobrescribir nombres de archivo permitidos. Con CVSS 9.8, afecta directamente a sitios empresariales, e-commerce y portales de clientes en LATAM que utilicen este plugin.