CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
FOMO in the SOC: Where AI Platforms like Claude Actually Fit
The Hacker News · 03 Ago 2026 ↗
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
The Hacker News · 03 Ago 2026 ↗
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Hacker News · 03 Ago 2026 ↗
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
The Hacker News · 03 Ago 2026 ↗
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
The Hacker News · 03 Ago 2026 ↗
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
The Hacker News · 03 Ago 2026 ↗
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2024-48248 NAKIVO Backup and Replication NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitr… ALTA 2025-03-19
CVE-2025-1316 Edimax IC-7100 IP Camera Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows … CRÍTICA 2025-03-19
CVE-2025-30066 tj-actions changed-files GitHub Action tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker … ALTA 2025-03-18
CVE-2025-24472 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain s… ALTA 2025-03-18
CVE-2025-21590 Juniper Junos OS Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows … MEDIA 2025-03-13
CVE-2025-24201 Apple Multiple Products Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allo… CRÍTICA 2025-03-13
CVE-2025-24993 Microsoft Windows Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an … ALTA 2025-03-11
CVE-2025-24991 Microsoft Windows Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authori… MEDIA 2025-03-11
CVE-2025-24985 Microsoft Windows Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an u… ALTA 2025-03-11
CVE-2025-24984 Microsoft Windows Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulner… MEDIA 2025-03-11
CVE-2025-24983 Microsoft Windows Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to … ALTA 2025-03-11
CVE-2025-26633 Microsoft Windows Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorize… ALTA 2025-03-11
CVE-2024-13161 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated at… CRÍTICA 2025-03-10
CVE-2024-13160 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated at… CRÍTICA 2025-03-10
CVE-2024-13159 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated at… CRÍTICA 2025-03-10
CVE-2024-57968 Advantive VeraCore Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to … CRÍTICA 2025-03-10
CVE-2025-25181 Advantive VeraCore Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execut… MEDIA 2025-03-10
CVE-2025-22226 VMware ESXi, Workstation, and Fusion VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HG… ALTA 2025-03-04
CVE-2025-22225 VMware ESXi VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges withi… ALTA 2025-03-04
CVE-2025-22224 VMware ESXi and Workstation VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an … CRÍTICA 2025-03-04
CVE-2024-50302 Linux Kernel The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory v… MEDIA 2025-03-04
CVE-2024-4885 Progress WhatsUp Gold Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote… CRÍTICA 2025-03-03
CVE-2018-8639 Microsoft Windows Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authent… ALTA 2025-03-03
CVE-2022-43769 Hitachi Vantara Pentaho Business Analytics (BA) Server Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject … ALTA 2025-03-03
CVE-2022-43939 Hitachi Vantara Pentaho Business Analytics (BA) Server Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability t… ALTA 2025-03-03
← Anterior Página 15 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·