CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2026-20316 Cisco Secure Firewall Management Center (FMC) Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-code… MEDIA 2026-07-29
CVE-2025-68686 Fortinet FortiOS Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a… MEDIA 2026-07-27
CVE-2026-16812 Arista VeloCloud Orchestrator Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker t… CRÍTICA 2026-07-27
CVE-2026-16232 Check Point SmartConsole Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote … CRÍTICA 2026-07-22
CVE-2026-50522 Microsoft SharePoint Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attac… CRÍTICA 2026-07-22
CVE-2026-60137 WordPress Core WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. T… MEDIA 2026-07-21
CVE-2026-63030 WordPress Core WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection … CRÍTICA 2026-07-21
CVE-2026-0770 Langflow Langflow Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attacker… CRÍTICA 2026-07-21
CVE-2021-27137 DD-WRT DD-WRT DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an… ALTA 2026-07-21
CVE-2026-58644 Microsoft SharePoint Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to… CRÍTICA 2026-07-16
CVE-2026-25089 Fortinet FortiSandbox Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that all… CRÍTICA 2026-07-16
CVE-2026-39808 Fortinet FortiSandbox Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to ex… CRÍTICA 2026-07-16
CVE-2026-46817 Oracle E-Business Suite Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker… CRÍTICA 2026-07-15
CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism… ALTA 2026-07-15
CVE-2026-56155 Microsoft Active Directory Federation Services Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability tha… ALTA 2026-07-14
CVE-2026-56164 Microsoft SharePoint Server Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized … MEDIA 2026-07-14
CVE-2026-15409 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthentica… CRÍTICA 2026-07-14
CVE-2026-15410 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enab… ALTA 2026-07-14
CVE-2008-4128 Cisco IOS Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary c… MEDIA 2026-07-13
CVE-2026-56291 Balbooa Forms Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated … CRÍTICA 2026-07-10
CVE-2026-48939 iCagenda iCagenda iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary … CRÍTICA 2026-07-10
CVE-2026-48908 JoomShaper SP Page Builder JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauth… CRÍTICA 2026-07-07
CVE-2026-55255 Langflow Langflow Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attac… CRÍTICA 2026-07-07
CVE-2026-56290 Joomlack Page Builder Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via … CRÍTICA 2026-07-07
CVE-2026-48282 Adobe ColdFusion Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of … CRÍTICA 2026-07-07
Página 1 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·