CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2013-3918 Microsoft Windows Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX contro… ALTA 2025-10-06
CVE-2011-3402 Microsoft Windows Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the… ALTA 2025-10-06
CVE-2010-3765 Mozilla Multiple Products Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allow… CRÍTICA 2025-10-06
CVE-2025-61882 Oracle E-Business Suite Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerabil… CRÍTICA 2025-10-06
CVE-2014-6278 GNU GNU Bash GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via… ALTA 2025-10-02
CVE-2017-1000353 Jenkins Jenkins Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a s… CRÍTICA 2025-10-02
CVE-2015-7755 Juniper ScreenOS Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative … CRÍTICA 2025-10-02
CVE-2025-21043 Samsung Mobile Devices Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attac… ALTA 2025-10-02
CVE-2025-4008 Smartbedded Meteobridge Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to… ALTA 2025-10-02
CVE-2025-32463 Sudo Sudo Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow… CRÍTICA 2025-09-29
CVE-2025-59689 Libraesva Email Security Gateway Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a … MEDIA 2025-09-29
CVE-2025-10035 Fortra GoAnywhere MFT Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged … CRÍTICA 2025-09-29
CVE-2025-20352 Cisco IOS and IOS XE Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SN… ALTA 2025-09-29
CVE-2021-21311 Adminer Adminer Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain p… ALTA 2025-09-29
CVE-2025-20362 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Serve… MEDIA 2025-09-25
CVE-2025-20333 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Serve… CRÍTICA 2025-09-25
CVE-2025-10585 Google Chromium V8 Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. CRÍTICA 2025-09-23
CVE-2025-5086 Dassault Systèmes DELMIA Apriso Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote … CRÍTICA 2025-09-11
CVE-2025-38352 Linux Kernel Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confi… ALTA 2025-09-04
CVE-2025-48543 Android Runtime Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local p… ALTA 2025-09-04
CVE-2025-53690 Sitecore Multiple Products Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deser… CRÍTICA 2025-09-04
CVE-2023-50224 TP-Link TL-WR841N TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens o… MEDIA 2025-09-03
CVE-2025-9377 TP-Link Multiple Routers TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Co… ALTA 2025-09-03
CVE-2020-24363 TP-Link TL-WA855RE TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allo… ALTA 2025-09-02
CVE-2025-55177 Meta Platforms WhatsApp Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked … MEDIA 2025-09-02
← Anterior Página 10 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·