Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Vim" — 23 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1815
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad de desbordamiento entero en GNU Emacs anterior a 31.0.91 permite fuga de memoria
GNU Emacs antes de la versión 31.0.91 contiene un desbordamiento de entero en el cargador de imágenes PBM/PPM/PGM que permite a un atacante acceder a contenido de memoria heap mediante imágenes manipuladas con dimensiones grandes e índices de color elevados. La vulnerabilidad resulta del uso de aritmética de enteros con signo en la multiplicación de dimensiones e canales de imagen, causando envolvimiento a valores negativos que eluden validaciones de seguridad.
M Alto vulnerabilidad
Hace 3 días
Vulnerabilidad alta en Multicluster Engine (MCE) permite eliminar clústeres sin autorización
Se identificó un fallo en el componente clusterclaims-controller de Multicluster Engine (MCE) que permite a usuarios con permisos estándar manipular el campo `spec.namespace` para especificar y eliminar cualquier ManagedCluster, incluyendo el hub local-cluster o clústeres de otros inquilinos. La ausencia de validación de propiedad (ownership check) expone infraestructuras multiclúster en entornos empresariales de México y LATAM a pérdida de disponibilidad y movimientos laterales entre tenants.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-43961] A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expressio…
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
M Crítico vulnerabilidad
10/08/2026
Inyección de comandos OS en crontab-ui v0.4.2 permite ejecución remota sin autenticación
Una vulnerabilidad crítica de inyección de comandos en crontab-ui afecta todas las versiones hasta la 0.4.2, permitiendo a atacantes no autenticados inyectar trabajos cron arbitrarios mediante solicitudes GET manipuladas al parámetro env_vars. Esta exposición es de alto riesgo para empresas en LATAM que usan este componente en infraestructuras de automatización, facilitando compromiso de servidores, exfiltración de datos y movimiento lateral en redes corporativas.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65543] Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
Subscriber Sensitive Data Exposure in Vimeo
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-18072] The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPre…
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied t…
M Alto vulnerabilidad
17/07/2026
[CVE-2026-12691] Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platfor…
Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-12692] Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentic…
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-12693] Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Pla…
Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-12694] Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Func…
Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
V Alto vulnerabilidad
09/07/2026
[CVE-2026-59856] Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script i…
Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honor…
V Alto vulnerabilidad
09/07/2026
[CVE-2026-59858] Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in …
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitr…
V Alto vulnerabilidad
25/06/2026
[CVE-2026-57455] Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_…
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stac…
V Alto vulnerabilidad
25/06/2026
[CVE-2026-57456] Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (ru…
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple…
V Alto vulnerabilidad
25/06/2026
[CVE-2026-55895] Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulne…
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash characte…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
V Alto vulnerabilidad
25/06/2026
[CVE-2026-55693] Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function …
Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount…
V Alto vulnerabilidad
11/06/2026
[CVE-2026-52858] Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completi…
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and from statements found in the current buffer through Python's import machinery. Because the buffer's working directory is …
V Alto vulnerabilidad
11/06/2026
[CVE-2026-52859] Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() fu…
Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stopping only when it encounters a NUL terminator. When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL …
V Alto vulnerabilidad
11/06/2026
[CVE-2026-52860] Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-comple…
Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default values, parameter annotations, and class base expressions at definition time, so a hostile buffer can execute attacker-con…
V Alto vulnerabilidad
11/06/2026
[CVE-2026-47162] Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injecti…
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string lit…