CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2025-25257 Fortinet FortiWeb Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthor… CRÍTICA 2025-07-18
CVE-2025-47812 Wing FTP Server Wing FTP Server Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injectio… CRÍTICA 2025-07-14
CVE-2025-5777 Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This… ALTA 2025-07-10
CVE-2019-9621 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServl… ALTA 2025-07-07
CVE-2019-5418 Rails Ruby on Rails Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combina… ALTA 2025-07-07
CVE-2016-10033 PHP PHPMailer PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, th… CRÍTICA 2025-07-07
CVE-2014-3931 Looking Glass Multi-Router Looking Glass (MRLG) Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause a… CRÍTICA 2025-07-07
CVE-2025-6554 Google Chromium V8 Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read… ALTA 2025-07-02
CVE-2025-48928 TeleMessage TM SGNL TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulner… MEDIA 2025-07-01
CVE-2025-48927 TeleMessage TM SGNL TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability… MEDIA 2025-07-01
CVE-2025-6543 Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial … CRÍTICA 2025-06-30
CVE-2019-6693 Fortinet FortiOS Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitiv… MEDIA 2025-06-25
CVE-2024-0769 D-Link DIR-859 Router D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Reques… MEDIA 2025-06-25
CVE-2024-54085 AMI MegaRAC SPx AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful… CRÍTICA 2025-06-25
CVE-2023-0386 Linux Kernel Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the… ALTA 2025-06-17
CVE-2023-33538 TP-Link Multiple Routers TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the compon… ALTA 2025-06-16
CVE-2025-43200 Apple Multiple Products Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously cra… MEDIA 2025-06-16
CVE-2025-33053 Microsoft Windows Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execu… ALTA 2025-06-10
CVE-2025-24016 Wazuh Wazuh Server Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers. CRÍTICA 2025-06-10
CVE-2024-42009 Roundcube Webmail RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to st… CRÍTICA 2025-06-09
CVE-2025-32433 Erlang Erlang/OTP Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an… CRÍTICA 2025-06-09
CVE-2025-5419 Google Chromium V8 Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potenti… ALTA 2025-06-05
CVE-2025-21479 Qualcomm Multiple Chipsets Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corru… ALTA 2025-06-03
CVE-2025-21480 Qualcomm Multiple Chipsets Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corru… ALTA 2025-06-03
CVE-2025-27038 Qualcomm Multiple Chipsets Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption whil… ALTA 2025-06-03
← Anterior Página 12 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·