CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
The Hacker News · 03 Ago 2026 ↗
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
The Hacker News · 03 Ago 2026 ↗
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
The Hacker News · 03 Ago 2026 ↗
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2021-32030 ASUS Routers ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to g… CRÍTICA 2025-06-02
CVE-2025-3935 ConnectWise ScreenConnect ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState… ALTA 2025-06-02
CVE-2025-35939 Craft CMS Craft CMS Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow… MEDIA 2025-06-02
CVE-2024-56145 Craft CMS Craft CMS Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution… CRÍTICA 2025-06-02
CVE-2023-39780 ASUS RT-AX55 Routers ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to… ALTA 2025-06-02
CVE-2025-4632 Samsung MagicINFO 9 Server Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as s… CRÍTICA 2025-05-22
CVE-2023-38950 ZKTeco BioTime ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to rea… ALTA 2025-05-19
CVE-2024-27443 Synacor Zimbra Collaboration Suite (ZCS) Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra we… MEDIA 2025-05-19
CVE-2025-27920 Srimax Output Messenger Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files … ALTA 2025-05-19
CVE-2024-11182 MDaemon Email Server MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrar… MEDIA 2025-05-19
CVE-2025-4428 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authe… ALTA 2025-05-19
CVE-2025-4427 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows … MEDIA 2025-05-19
CVE-2025-42999 SAP NetWeaver SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attac… CRÍTICA 2025-05-15
CVE-2024-12987 DrayTek Vigor Routers DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown fun… ALTA 2025-05-15
CVE-2025-32756 Fortinet Multiple Products Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a re… CRÍTICA 2025-05-14
CVE-2025-32709 Microsoft Windows Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authoriz… ALTA 2025-05-13
CVE-2025-30397 Microsoft Windows Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to exec… ALTA 2025-05-13
CVE-2025-32706 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows … ALTA 2025-05-13
CVE-2025-32701 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorize… ALTA 2025-05-13
CVE-2025-30400 Microsoft Windows Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevat… ALTA 2025-05-13
CVE-2025-47729 TeleMessage TM SGNL TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies… BAJA 2025-05-12
CVE-2024-11120 GeoVision Multiple Devices Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker… CRÍTICA 2025-05-07
CVE-2024-6047 GeoVision Multiple Devices Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker… CRÍTICA 2025-05-07
CVE-2025-27363 FreeType FreeType FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to Tru… ALTA 2025-05-06
CVE-2025-3248 Langflow Langflow Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, un… CRÍTICA 2025-05-05
← Anterior Página 13 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·