Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Encode" — 45 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-107823] MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 1…
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the MariaDB view FRM parser did not safely encode embedded newline characters in a username. An account with CREATE USER and CREATE VIEW WITH GRANT OPTION could create a crafted username containing additional view metadata, causing the parser to interpret part of …
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107383] MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL …
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop sk…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107611] An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows befo…
An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-16340] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106115] ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocate…
ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax a…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106110] ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocate…
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited fro…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105086] WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows aut…
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad alta de ejecución remota de código en W (wcms) versión 3.18.0 y anteriores
W (vincent-peugnet/wcms) versión 3.18.0 y anteriores contiene una vulnerabilidad de ejecución remota de código (RCE) que permite a editores autenticados escribir archivos arbitrarios mediante la validación insuficiente en POST /api/v0/media/upload/[*:path]. Los atacantes pueden cargar archivos PHP ejecutables, utilizar secuencias codificadas ../ para escribir fuera del directorio de medios, y eliminar archivos arbitrarios. Esta vulnerabilidad afecta principalmente a plataformas de gestión de contenidos desplegadas en servidores web de empresas mexicanas y latinoamericanas.
M Alto vulnerabilidad
03/10/2026
[CVE-2026-104478] Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authe…
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-19660] The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up t…
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled …
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta de acumulación de memoria en Tornado anterior a 6.5.9
Tornado versions anteriores a 6.5.9 contienen una vulnerabilidad de acumulación ilimitada de memoria en CurlAsyncHTTPClient que permite a atacantes remotos causar denegación de servicio. Los atacantes pueden enviar bombas de descompresión gzip que se acumulan sin límites en memoria, provocando que el proceso de la aplicación sea terminado por condiciones de falta de memoria. Esto afecta directamente a aplicaciones web y APIs en producción que procesan respuestas comprimidas sin validación de tamaño.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103088] Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, th…
Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102810] Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by -…
Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder, enabling attackers to request encoded traversal sequences to access files readable …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-63209] compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow…
compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Point…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100706] kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath…
kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100707] Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespac…
Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-segments in urlPath to bypass namespace checks and read resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100661] Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain …
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of continuation bytes it will process. A remote, unauthenticated peer can open a QPACK unidirectional stream (type 0x02 encoder or 0x03 decoder) and send a first…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100662] Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain …
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-initiated unidirectional QPACK encoder stream, type 0x02). The handler accepts an attacker-declared string-literal length of up to Integer.MAX_VALUE (~2 GiB)…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100660] Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbo…
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID, and these entries are released only when the remote decoder sends a Section Acknow…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-92608] Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows…
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.