Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 10 min
Buscando: "Multiple Vendors" — 8747 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1724
Esta semana
RSS
M Alto vulnerabilidad
03/07/2026
[CVE-2026-26307] Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searc…
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27657] Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27660] Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the requ…
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-22555] Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first…
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-22874] Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration a…
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24451] Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public t…
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24690] Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull reque…
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-25038] Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-25712] Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for…
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-25718] Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowi…
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-20706] Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope c…
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-20779] Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a vali…
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-20896] Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by defaul…
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-22547] Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including l…
Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14605] A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the funct…
A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14606] A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function…
A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the library bsp/synwit/libraries/SWM341_CSL/CMSIS/DeviceSupport/SWM341.h of the component SWM341 CAN Handler. Performing a manipulation results in stack-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for a…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58379] A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulner…
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an ov…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14459] Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in …
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14460] Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardu…
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-56015] Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix …
Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. addPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) pa…