CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2025-57819 Sangoma FreePBX Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allo… CRÍTICA 2025-08-29
CVE-2025-7775 Citrix NetScaler Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code exe… CRÍTICA 2025-08-26
CVE-2025-48384 Git Git Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters i… ALTA 2025-08-25
CVE-2024-8068 Citrix Session Recording Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalat… ALTA 2025-08-25
CVE-2024-8069 Citrix Session Recording Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code exe… ALTA 2025-08-25
CVE-2025-43300 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. CRÍTICA 2025-08-21
CVE-2025-54948 Trend Micro Apex One Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a … CRÍTICA 2025-08-18
CVE-2025-8876 N-able N-Central N-able N-Central contains a command injection vulnerability via improper sanitization of user input. ALTA 2025-08-13
CVE-2025-8875 N-able N-Central N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. ALTA 2025-08-13
CVE-2025-8088 RARLAB WinRAR RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could… ALTA 2025-08-12
CVE-2007-0671 Microsoft Office Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Ex… ALTA 2025-08-12
CVE-2013-3893 Microsoft Internet Explorer Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impac… ALTA 2025-08-12
CVE-2020-25078 D-Link DCS-2530L and DCS-2670L Devices D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator … ALTA 2025-08-05
CVE-2020-25079 D-Link DCS-2530L and DCS-2670L Devices D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impa… ALTA 2025-08-05
CVE-2022-40799 D-Link DNR-322L D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated att… ALTA 2025-08-05
CVE-2023-2533 PaperCut NG/MF PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could pote… ALTA 2025-07-28
CVE-2025-20337 Cisco Identity Services Engine Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due… CRÍTICA 2025-07-28
CVE-2025-20281 Cisco Identity Services Engine Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due… CRÍTICA 2025-07-28
CVE-2025-2775 SysAid SysAid On-Prem SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processin… CRÍTICA 2025-07-22
CVE-2025-2776 SysAid SysAid On-Prem SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL proces… CRÍTICA 2025-07-22
CVE-2025-6558 Google Chromium Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a … ALTA 2025-07-22
CVE-2025-54309 CrushFTP CrushFTP CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS… CRÍTICA 2025-07-22
CVE-2025-49704 Microsoft SharePoint Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code ov… ALTA 2025-07-22
CVE-2025-49706 Microsoft SharePoint Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform sp… MEDIA 2025-07-22
CVE-2025-53770 Microsoft SharePoint Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an … CRÍTICA 2025-07-20
← Anterior Página 11 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·