CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
The Hacker News · 03 Ago 2026 ↗
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Hacker News · 03 Ago 2026 ↗
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
The Hacker News · 03 Ago 2026 ↗
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
The Hacker News · 03 Ago 2026 ↗
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
The Hacker News · 03 Ago 2026 ↗
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2025-34028 Commvault Command Center Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to exec… CRÍTICA 2025-05-02
CVE-2024-58136 Yiiframework Yii Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execu… CRÍTICA 2025-05-02
CVE-2024-38475 Apache HTTP Server Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map … CRÍTICA 2025-05-01
CVE-2023-44221 SonicWall SMA100 Appliances SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allo… ALTA 2025-05-01
CVE-2025-31324 SAP NetWeaver SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unaut… CRÍTICA 2025-04-29
CVE-2025-1976 Broadcom Brocade Fabric OS Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privile… MEDIA 2025-04-28
CVE-2025-42599 Qualitia Active! Mail Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attack… CRÍTICA 2025-04-28
CVE-2025-3928 Commvault Web Server Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and e… ALTA 2025-04-28
CVE-2025-24054 Microsoft Windows Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized atta… MEDIA 2025-04-17
CVE-2025-31201 Apple Multiple Products Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an att… CRÍTICA 2025-04-17
CVE-2025-31200 Apple Multiple Products Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execu… CRÍTICA 2025-04-17
CVE-2021-20035 SonicWall SMA100 Appliances SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a rem… MEDIA 2025-04-16
CVE-2024-53150 Linux Kernel Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attac… ALTA 2025-04-09
CVE-2024-53197 Linux Kernel Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physic… ALTA 2025-04-09
CVE-2025-29824 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorize… ALTA 2025-04-08
CVE-2025-30406 Gladinet CentreStack Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the appli… CRÍTICA 2025-04-08
CVE-2025-31161 CrushFTP CrushFTP CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthen… CRÍTICA 2025-04-07
CVE-2025-22457 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows… CRÍTICA 2025-04-04
CVE-2025-24813 Apache Tomcat Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose informa… CRÍTICA 2025-04-01
CVE-2024-20439 Cisco Smart Licensing Utility Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacke… CRÍTICA 2025-03-31
CVE-2025-2783 Google Chromium Mojo Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an … ALTA 2025-03-27
CVE-2019-9875 Sitecore CMS and Experience Platform (XP) Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF mod… ALTA 2025-03-26
CVE-2019-9874 Sitecore CMS and Experience Platform (XP) Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF mod… CRÍTICA 2025-03-26
CVE-2025-30154 reviewdog action-setup GitHub Action reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Gi… ALTA 2025-03-24
CVE-2017-12637 SAP NetWeaver SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca4… ALTA 2025-03-19
← Anterior Página 14 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·