Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Coder" — 166 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84447] libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iov…
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84383] libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF…
libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths to m_storage. HeifPixelImage::scale_nearest_neighbor() in libheif/image/pixelimage.cc allocates the destination Alpha pla…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84384] libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF o…
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective size limit or MemoryHandle accounting. The brotli path has no output bound, while the zlib path checks only a small temporary buffer in a branch that valid streams …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63419] OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format…
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A zbuffer-only tiled iff is exposed with a 16-bit public imagespec while the decoder retains a 32-bit internal pixel size. iffinput::read_native_tile() copies according to m_header.pixel_bytes() rather than imagespec::tile…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93575] ### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `…
### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` exceeds `maxBytesInMessage`, but fails to validate the `Properties Length` against the `Remaining Length`. An attacker can bypass the size limit by sending a small `Remaining Length` but an enormous `Properties Length`. This forces Netty to buffer and parse millions of properties, …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93563] Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoS
Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoS
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad alta en Netty: fuga de memoria en StompSubframeDecoder (CVE-2026-93494)
Se identificó un fallo en el componente StompSubframeDecoder de Netty que permite a atacantes remotos provocar una fuga permanente de memoria mediante frames STOMP malformados sin byte nulo de terminación. La acumulación descontrolada de memoria puede derivar en Denegación de Servicio (DoS), afectando aplicaciones que utilizan este framework para procesamiento de mensajes en tiempo real, especialmente en plataformas de comercio electrónico, sistemas financieros y comunicaciones altas en la región.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-84997] react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.…
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete terminal-chunk trailer without CRLF left the buffer unchanged after strpos retur…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89873] In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEV…
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC EXT SPS RPS counts The HEVC SPS control carries the short-term and long-term RPS counts that decoder drivers use to walk the matching EXT SPS dynamic arrays. Reject SPS values that exceed the HEVC limits of 64 short-term sets and 32 long-term references so drivers cannot later index beyond those …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-69210] Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTransc…
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that completes a WebSocket handshake through an Ember server can send such a frame, causing the decoder to return an empty frame without advancing its input. The decode loop …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-69209] Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket …
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote client that completes a WebSocket handshake against an http4s-blaze-server or http4s-ember-server endpoint can exhaust s…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-56974] In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper …
In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-63443] Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29…
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's U…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57586] CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior t…
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and p…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82435] Description The worker's Netty message decoder is installed ahead of the SASL authentication handle…
Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker slot port could drive a large allocation. `storm.messaging.netty.authentication…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-23789] An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, …
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.
M Alto vulnerabilidad
12/09/2026
Desbordamiento de búfer en stb_vorbis 1.22 permite corrupción de memoria
stb_vorbis versiones hasta 1.22 contiene un desbordamiento de búfer en la función start_decoder() donde el tamaño de asignación de multiplicandos de codebook se trunca de size_t a int. Atacantes pueden crear archivos Ogg Vorbis maliciosos con valores grandes de entradas y dimensiones para provocar escrituras fuera de límites, causando fallos de proceso o corrupción de heap. Afecta aplicaciones de audio y streaming en servidores empresariales de México y LATAM.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libde265 permite desbordamiento de enteros en procesamiento de video HEVC
libde265 versiones anteriores a 1.1.1 contienen un fallo de desbordamiento de enteros en cálculo de desplazamientos de píxeles que permite a archivos HEVC malformados con dimensiones grandes provocar lecturas/escrituras fuera de límites en memoria heap. El impacto incluye exposición de datos sensibles, corrupción de memoria o crasheo del decodificador afectando plataformas de procesamiento de video, streaming y análisis multimedia en operaciones en LATAM.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64836] ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint du…
ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated attackers to submit traversal sequences or absolute paths in the file parameter to read, write, or delete files outside t…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64837] ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php,…
ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as the web-server user via popen().