Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Coder" — 143 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad alta en Netty: fuga de memoria en StompSubframeDecoder (CVE-2026-93494)
Se identificó un fallo en el componente StompSubframeDecoder de Netty que permite a atacantes remotos provocar una fuga permanente de memoria mediante frames STOMP malformados sin byte nulo de terminación. La acumulación descontrolada de memoria puede derivar en Denegación de Servicio (DoS), afectando aplicaciones que utilizan este framework para procesamiento de mensajes en tiempo real, especialmente en plataformas de comercio electrónico, sistemas financieros y comunicaciones altas en la región.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-84997] react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.…
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete terminal-chunk trailer without CRLF left the buffer unchanged after strpos retur…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89873] In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEV…
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC EXT SPS RPS counts The HEVC SPS control carries the short-term and long-term RPS counts that decoder drivers use to walk the matching EXT SPS dynamic arrays. Reject SPS values that exceed the HEVC limits of 64 short-term sets and 32 long-term references so drivers cannot later index beyond those …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-69210] Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTransc…
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that completes a WebSocket handshake through an Ember server can send such a frame, causing the decoder to return an empty frame without advancing its input. The decode loop …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-69209] Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket …
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote client that completes a WebSocket handshake against an http4s-blaze-server or http4s-ember-server endpoint can exhaust s…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-56974] In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper …
In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-63443] Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29…
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's U…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57586] CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior t…
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and p…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-23789] An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, …
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.
M Alto vulnerabilidad
12/09/2026
Desbordamiento de búfer en stb_vorbis 1.22 permite corrupción de memoria
stb_vorbis versiones hasta 1.22 contiene un desbordamiento de búfer en la función start_decoder() donde el tamaño de asignación de multiplicandos de codebook se trunca de size_t a int. Atacantes pueden crear archivos Ogg Vorbis maliciosos con valores grandes de entradas y dimensiones para provocar escrituras fuera de límites, causando fallos de proceso o corrupción de heap. Afecta aplicaciones de audio y streaming en servidores empresariales de México y LATAM.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libde265 permite desbordamiento de enteros en procesamiento de video HEVC
libde265 versiones anteriores a 1.1.1 contienen un fallo de desbordamiento de enteros en cálculo de desplazamientos de píxeles que permite a archivos HEVC malformados con dimensiones grandes provocar lecturas/escrituras fuera de límites en memoria heap. El impacto incluye exposición de datos sensibles, corrupción de memoria o crasheo del decodificador afectando plataformas de procesamiento de video, streaming y análisis multimedia en operaciones en LATAM.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64836] ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint du…
ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated attackers to submit traversal sequences or absolute paths in the file parameter to read, write, or delete files outside t…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64837] ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php,…
ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as the web-server user via popen().
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64838] ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and r…
ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable by the PHP process into the web-accessible project directory, disclosing file contents and deleting originals.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42807] A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINE…
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue_…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-79377] A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio…
A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86541] knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() func…
knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or SSH configuration files.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad de desbordamiento de memoria en HTTPX2 anterior a versión 2.12.0 (CVE-2026-84382)
HTTPX2, cliente HTTP de nueva generación para Python, contiene una vulnerabilidad en sus decodificadores de contenido (gzip, deflate, br, zstd) que permite ataques de denegación de servicio. Fragmentos comprimidos de 64 KiB pueden expandirse hasta 64 MiB en memoria, causando consumo excesivo de recursos en servidores y aplicaciones Python. Afecta principalmente a infraestructuras que procesan contenido comprimido desde orígenes no confiables.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-73108] RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability i…
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823 bytes of capacity, allowing unauthenticated attackers to use concurrent TCP connectio…
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad de replay attack en Spring Security afecta aplicaciones Java
Spring Security contiene una vulnerabilidad de caché que permite ataques de reproducción (replay) contra tokens DPoP (Demonstrating Proof-of-Possession). Un atacante puede desalojar entradas legítimas del caché mediante inundación de solicitudes, para luego reutilizar pruebas DPoP válidas interceptadas. Afecta versiones 6.5.0-6.5.11, 7.0.0-7.0.6 y 7.1.0. El riesgo es alta en sistemas de autenticación OAuth 2.0 y APIs sensibles en instituciones financieras y plataformas de gobierno digital de LATAM.