Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Gnu" — 23 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1764
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
Vulnerabilidad de desbordamiento entero en GNU Emacs anterior a 31.0.91 permite fuga de memoria
GNU Emacs antes de la versión 31.0.91 contiene un desbordamiento de entero en el cargador de imágenes PBM/PPM/PGM que permite a un atacante acceder a contenido de memoria heap mediante imágenes manipuladas con dimensiones grandes e índices de color elevados. La vulnerabilidad resulta del uso de aritmética de enteros con signo en la multiplicación de dimensiones e canales de imagen, causando envolvimiento a valores negativos que eluden validaciones de seguridad.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-61898] The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accounts…
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of t…
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad en FileBrowser anterior a 2.63.19 permite creación de cuentas duplicadas en sistemas Windows
FileBrowser versiones anteriores a 2.63.19 no valida correctamente nombres de usuario en sistemas de archivos sin distinción entre mayúsculas y minúsculas (NTFS/Windows). Cuando están habilitados el registro automático y la creación de directorios de usuario, un atacante puede registrar múltiples cuentas con nombres idénticos pero diferente capitalización (ej: Admin y admin), comprometiendo la integridad del control de acceso. Afecta principalmente a servidores Windows y NAS con configuraciones de acceso público en LATAM.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73566] node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter …
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filt…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-19211] A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown functio…
A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-18220] An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c…
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation …
M Alto vulnerabilidad
28/07/2026
[CVE-2026-59932] PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 th…
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the Gnumeric reader reads attacker-supplied .gnumeric files into memory and, when the file starts with gzip magic bytes, calls gzdecode() on the full compressed contents without…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-60122] gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the…
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to t…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-16607] A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before v…
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
M Alto vulnerabilidad
18/07/2026
[CVE-2026-10130] QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to…
QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditionally creates and links a new token to the matching Identity via a Cypher MERGE operation before checking whether the email belongs to an existing account, …
M Alto vulnerabilidad
18/07/2026
[CVE-2024-58362] SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signi…
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthenticated attacker can encode a binary object containing a subquery using the bincode…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-13741] The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege…
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administr…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-62685] File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing…
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signup=true and CreateUserDir=true, but the many-to-one normalization can collapse usernames such as team/one, team one, and team-one to the same home directo…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-47164] Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO log…
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an attacker-controlled IdP identity asserting a victim email address to bind to and authenticate as that account. This issue…
D Alto vulnerabilidad
09/07/2026
[CVE-2026-44787] Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5…
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Alto vulnerabilidad
09/07/2026
[CVE-2026-58459] gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in …
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnup…
G Alto vulnerabilidad
07/07/2026
[CVE-2026-58469] GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in …
GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespa…
G Alto vulnerabilidad
29/06/2026
[CVE-2026-41992] GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by im…
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a spe…
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53136] In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HD…
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size [Why & How] The VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and Hdmi6GRegNum fields that are used as loop bounds when copying retimer I2C register settings into fixed-size arrays (dp*_ext_hdmi_reg_settings[9] and dp*_ext_hdmi_6g_reg_setti…
G Alto vulnerabilidad
25/06/2026
[CVE-2026-9154] Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated…
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.