CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
The Hacker News · 30 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2026-45659 Microsoft SharePoint Server Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attac… ALTA 2026-07-01
CVE-2026-48558 SimpleHelp SimpleHelp SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is… CRÍTICA 2026-06-29
CVE-2026-12569 PTC Windchill and FlexPLM PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attac… CRÍTICA 2026-06-25
CVE-2026-20230 Cisco Unified Communications Manager Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (… ALTA 2026-06-25
CVE-2025-67038 Lantronix EDS5000 Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands in… CRÍTICA 2026-06-23
CVE-2026-34910 Ubiquiti UniFi OS Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access t… CRÍTICA 2026-06-23
CVE-2026-34909 Ubiquiti UniFi OS Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the networ… CRÍTICA 2026-06-23
CVE-2026-34908 Ubiquiti UniFi OS Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to … CRÍTICA 2026-06-23
CVE-2026-20253 Splunk Enterprise Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenti… CRÍTICA 2026-06-18
CVE-2026-48907 Widget Factory Joomla Content Editor Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and… CRÍTICA 2026-06-16
CVE-2026-54420 LiteSpeed cPanel Plugin LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FT… ALTA 2026-06-15
CVE-2026-20262 Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, r… MEDIA 2026-06-15
CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which co… CRÍTICA 2026-06-12
CVE-2026-10520 Ivanti Sentry Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a … CRÍTICA 2026-06-11
CVE-2026-11645 Google Chromium V8 Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary c… ALTA 2026-06-09
CVE-2026-7473 Arista Extensible Operating System Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the … MEDIA 2026-06-09
CVE-2026-20245 Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability… ALTA 2026-06-09
CVE-2026-42271 BerriAI LiteLLM BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders o… ALTA 2026-06-08
CVE-2026-50751 Check Point Security Gateway Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow a… CRÍTICA 2026-06-08
CVE-2026-28318 SolarWinds Serv-U SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST reques… ALTA 2026-06-05
CVE-2026-45247 Mirasvit Mirasvit Full Page Cache Warmer Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthentic… CRÍTICA 2026-06-03
CVE-2022-0492 Linux Kernel Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgrou… ALTA 2026-06-02
CVE-2025-48595 Android Framework Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local … ALTA 2026-06-02
CVE-2024-21182 Oracle WebLogic Server Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access … ALTA 2026-06-01
CVE-2026-0257 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security rest… CRÍTICA 2026-05-29
← Anterior Página 2 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·