// threat_intelligence_dashboard
Dashboard de Amenazas
Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)
▶ ¿Cómo se calcula el nivel de amenaza global?
El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:
- 🟢 BAJA — 0 CVEs nuevos en el feed reciente
- 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
- 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
- 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados
Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.
15
CVEs añadidos este mes
1622
Total KEV catalogados
10
Vendors afectados
// cves_añadidos_este_mes
| CVE | Producto | Criticidad | Añadido |
|---|---|---|---|
| CVE-2026-48907 | Widget Factory Joomla Content Editor | — | 2026-06-16 |
| CVE-2026-54420 | LiteSpeed cPanel Plugin | ALTA | 2026-06-15 |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | MEDIA | 2026-06-15 |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools | CRÍTICA | 2026-06-12 |
| CVE-2026-10520 | Ivanti Sentry | CRÍTICA | 2026-06-11 |
| CVE-2026-11645 | Google Chromium V8 | ALTA | 2026-06-09 |
| CVE-2026-7473 | Arista Extensible Operating System | MEDIA | 2026-06-09 |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager | ALTA | 2026-06-09 |
| CVE-2026-42271 | BerriAI LiteLLM | ALTA | 2026-06-08 |
| CVE-2026-50751 | Check Point Security Gateway | CRÍTICA | 2026-06-08 |
// top_vendors_afectados
16
9
6
4
4
3
2
2
2
2
// catalogo_kev_completo
| CVE ID | Producto | CVSS |
|---|---|---|
| CVE-2025-8088 | RARLAB WinRAR | ALTA |
| CVE-2007-0671 | Microsoft Office | ALTA |
| CVE-2013-3893 | Microsoft Internet Explorer | ALTA |
| CVE-2020-25078 | D-Link DCS-2530L and DCS-2670L Devices | ALTA |
| CVE-2020-25079 | D-Link DCS-2530L and DCS-2670L Devices | ALTA |
| CVE-2022-40799 | D-Link DNR-322L | ALTA |
| CVE-2023-2533 | PaperCut NG/MF | ALTA |
| CVE-2025-20337 | Cisco Identity Services Engine | CRÍTICA |
| CVE-2025-20281 | Cisco Identity Services Engine | CRÍTICA |
| CVE-2025-2775 | SysAid SysAid On-Prem | CRÍTICA |
| CVE-2025-2776 | SysAid SysAid On-Prem | CRÍTICA |
| CVE-2025-6558 | Google Chromium | ALTA |
| CVE-2025-54309 | CrushFTP CrushFTP | CRÍTICA |
| CVE-2025-49704 | Microsoft SharePoint | ALTA |
| CVE-2025-49706 | Microsoft SharePoint | MEDIA |
| CVE-2025-53770 | Microsoft SharePoint | CRÍTICA |
| CVE-2025-25257 | Fortinet FortiWeb | CRÍTICA |
| CVE-2025-47812 | Wing FTP Server Wing FTP Server | CRÍTICA |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | ALTA |
| CVE-2019-9621 | Synacor Zimbra Collaboration Suite (ZCS) | ALTA |
| CVE-2019-5418 | Rails Ruby on Rails | ALTA |
| CVE-2016-10033 | PHP PHPMailer | CRÍTICA |
| CVE-2014-3931 | Looking Glass Multi-Router Looking Glass (MRLG) | CRÍTICA |
| CVE-2025-6554 | Google Chromium V8 | ALTA |
| CVE-2025-48928 | TeleMessage TM SGNL | MEDIA |