CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

9
CVEs añadidos este mes
1665
Total KEV catalogados
10
Vendors afectados
CVE Producto Criticidad Añadido
CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) ALTA 2026-08-11
CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock ALTA 2026-08-11
CVE-2026-72898 Metabase Metabase CRÍTICA 2026-08-11
CVE-2026-8037 Progress LoadMaster CRÍTICA 2026-08-07
CVE-2026-63077 JetBrains TeamCity CRÍTICA 2026-08-05
CVE-2026-18556 N-able N-central ALTA 2026-08-04
CVE-2026-34486 Apache Tomcat ALTA 2026-08-04
CVE-2026-9198 IBM Langflow CRÍTICA 2026-08-04
CVE-2026-18577 N-able N-central ALTA 2026-08-03
Microsoft
18
Cisco
10
Fortinet
3
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
JetBrains
2
N-able
2
Apache
2
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
The Hacker News · 13 Ago 2026 ↗
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The Hacker News · 12 Ago 2026 ↗
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
The Hacker News · 12 Ago 2026 ↗
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
The Hacker News · 12 Ago 2026 ↗
Enterprise Defenses Recovered at the Edge and Collapsed Inside
The Hacker News · 12 Ago 2026 ↗
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
The Hacker News · 12 Ago 2026 ↗
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
The Hacker News · 12 Ago 2026 ↗
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
The Hacker News · 12 Ago 2026 ↗
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
The Hacker News · 12 Ago 2026 ↗
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
The Hacker News · 12 Ago 2026 ↗
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
The Hacker News · 12 Ago 2026 ↗
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
The Hacker News · 11 Ago 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2026-15409 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthentica… CRÍTICA 2026-07-14
CVE-2026-15410 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enab… ALTA 2026-07-14
CVE-2008-4128 Cisco IOS Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary c… MEDIA 2026-07-13
CVE-2026-56291 Balbooa Forms Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated … CRÍTICA 2026-07-10
CVE-2026-48939 iCagenda iCagenda iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary … CRÍTICA 2026-07-10
CVE-2026-48908 JoomShaper SP Page Builder JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauth… CRÍTICA 2026-07-07
CVE-2026-55255 Langflow Langflow Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attac… CRÍTICA 2026-07-07
CVE-2026-56290 Joomlack Page Builder Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via … CRÍTICA 2026-07-07
CVE-2026-48282 Adobe ColdFusion Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of … CRÍTICA 2026-07-07
CVE-2026-45659 Microsoft SharePoint Server Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attac… ALTA 2026-07-01
CVE-2026-48558 SimpleHelp SimpleHelp SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is… CRÍTICA 2026-06-29
CVE-2026-12569 PTC Windchill and FlexPLM PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attac… CRÍTICA 2026-06-25
CVE-2026-20230 Cisco Unified Communications Manager Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (… ALTA 2026-06-25
CVE-2025-67038 Lantronix EDS5000 Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands in… CRÍTICA 2026-06-23
CVE-2026-34910 Ubiquiti UniFi OS Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access t… CRÍTICA 2026-06-23
CVE-2026-34909 Ubiquiti UniFi OS Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the networ… CRÍTICA 2026-06-23
CVE-2026-34908 Ubiquiti UniFi OS Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to … CRÍTICA 2026-06-23
CVE-2026-20253 Splunk Enterprise Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenti… CRÍTICA 2026-06-18
CVE-2026-48907 Widget Factory Joomla Content Editor Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and… CRÍTICA 2026-06-16
CVE-2026-54420 LiteSpeed cPanel Plugin LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FT… ALTA 2026-06-15
CVE-2026-20262 Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, r… MEDIA 2026-06-15
CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which co… CRÍTICA 2026-06-12
CVE-2026-10520 Ivanti Sentry Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a … CRÍTICA 2026-06-11
CVE-2026-11645 Google Chromium V8 Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary c… ALTA 2026-06-09
CVE-2026-7473 Arista Extensible Operating System Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the … MEDIA 2026-06-09
← Anterior Página 2 / 67 (1665 CVEs total) Siguiente →
[INFO] CVE-2026-20349: Vulnerabilidad Crítica de Heap Inspection en Cisco ASA y FTD Explotada Activamente  ·  [INFO] CVE-2026-72898: Inyección SQL Crítica en Metabase Permite Acceso de Administrador Sin Autenticación  ·  [INFO] CVE-2026-68820: Use-After-Free en Windows WinSock Driver permite escalada de privilegios local  ·  [INFO] CVE-2026-8037: Inyección de Comandos Crítica en Progress LoadMaster Explotada Activamente  ·  [INFO] CVE-2026-63077: Vulnerabilidad Crítica de Deserialización en JetBrains TeamCity con RCE No Autenticado  ·  [INFO] CVE-2026-20349: Vulnerabilidad Crítica de Heap Inspection en Cisco ASA y FTD Explotada Activamente  ·  [INFO] CVE-2026-72898: Inyección SQL Crítica en Metabase Permite Acceso de Administrador Sin Autenticación  ·  [INFO] CVE-2026-68820: Use-After-Free en Windows WinSock Driver permite escalada de privilegios local  ·  [INFO] CVE-2026-8037: Inyección de Comandos Crítica en Progress LoadMaster Explotada Activamente  ·  [INFO] CVE-2026-63077: Vulnerabilidad Crítica de Deserialización en JetBrains TeamCity con RCE No Autenticado  ·