Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Perl" — 112 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
[CVE-2026-74766] Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decod…
Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buffer of the scalar it returns. decode_punycode computes the insertion pointer first and only then grows the buffer when the code point does not fit. The growth reall…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-87078] Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejecte…
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the three croaks that reject a label leaves the scalar and its buffer allocated. Nothing…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-87079] Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost …
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan runs once per code point over the output built so far, so the cost is quadratic i…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-87080] Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing …
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string returns the empty string rather than undef, so decoding continues past the end. …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-87081] Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding …
Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and only then applies the 63-byte DNS limit. encode_punycode in both backends follows the sample implementation in RFC 3492, whose outer loop runs once per distinct non-ASCII code point and scans the whol…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-87082] Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidate…
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over malformed bytes, as the :utf8 PerlIO layer produces from any malformed input, reaches the encoder unchecked. On perl 5.32 and later the XS backend reports a mal…
M Crítico vulnerabilidad
22/09/2026
[CVE-2016-15059] Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes …
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-93710] Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when th…
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cleanup unless the failing hook is the exception handler. A handler that halts does not stop that cleanup, which discards the request, response and session the dispatcher has yet to r…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-93712] Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative p…
Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and checks only that the result is a readable regular file. A request for `/../outside.txt` escapes public_dir, and percent-encoding the dots reaches the same file. The …
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94623] vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix cachin…
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of va…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94627] vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when co…
vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitting completion requests with multiple prompts, causing orphaned KV cache blocks to accumulate until process restart and eventually preventing legitima…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94495] jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemCon…
jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering company identity, stock rules, approval behavior, and printing configuration through the systemConfig endpoint.
M Crítico vulnerabilidad
19/09/2026
[CVE-2026-78030] DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm att…
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::…
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución de shortcodes en ProfilePress para WordPress
El plugin ProfilePress para WordPress (versiones hasta 4.17.2) es vulnerable a ejecución arbitraria de shortcodes por usuarios autenticados debido a validación insuficiente antes de ejecutar do_shortcode. Esta vulnerabilidad afecta sitios de e-commerce, formularios de registro y portales de contenido restringido ampliamente utilizados en LATAM. Un atacante autenticado podría inyectar código malicioso que se ejecute en el contexto del sitio WordPress.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica en plugin Forminator para WordPress permite ejecución arbitraria de shortcodes
El plugin Forminator Forms para WordPress (versiones hasta 1.57.2) es vulnerable a ejecución arbitraria de shortcodes debido a validación insuficiente en la función do_shortcode. Atacantes no autenticados pueden ejecutar código malicioso en sitios web afectados, comprometiendo la integridad de formularios de contacto y pago. Esta vulnerabilidad impacta directamente a empresas en LATAM que utilizan este plugin en formularios críticos de recolección de datos y procesamiento de pagos.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93753] deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function t…
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without ow…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93748] http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when pro…
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zero…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-91127] File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and…
File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink targets into generated HTML after character escaping but without restricting URL schemes. A crafted legacy DOC file could place javascript:, vbscript:, da…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-75031] In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was fou…
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is …
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93019] Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 327…
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3)…