CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2026-48027 Nx Nx Console Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be publi… CRÍTICA 2026-05-27
CVE-2026-45321 TanStack TanStack TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the np… CRÍTICA 2026-05-27
CVE-2026-8398 Daemon Daemon Tools Lite Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availabili… CRÍTICA 2026-05-27
CVE-2026-48172 LiteSpeed cPanel Plugin LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, whi… CRÍTICA 2026-05-26
CVE-2026-9082 Drupal Core Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution … MEDIA 2026-05-22
CVE-2025-34291 Langflow Langflow Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined wi… ALTA 2026-05-21
CVE-2026-34926 Trend Micro Apex One Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated loc… MEDIA 2026-05-21
CVE-2008-4250 Microsoft Windows Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers t… CRÍTICA 2026-05-20
CVE-2009-1537 Microsoft DirectX Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in Di… ALTA 2026-05-20
CVE-2009-3459 Adobe Acrobat and Reader Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execu… ALTA 2026-05-20
CVE-2010-0249 Microsoft Internet Explorer Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbit… ALTA 2026-05-20
CVE-2010-0806 Microsoft Internet Explorer Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbit… ALTA 2026-05-20
CVE-2026-41091 Microsoft Defender Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges loc… ALTA 2026-05-20
CVE-2026-45498 Microsoft Defender Microsoft Defender contains an unspecified vulnerability that allows for denial of service. MEDIA 2026-05-20
CVE-2026-42897 Microsoft Microsoft Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Acces… ALTA 2026-05-15
CVE-2026-20182 Cisco Catalyst SD-WAN Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticate… CRÍTICA 2026-05-14
CVE-2026-42208 BerriAI LiteLLM BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database a… CRÍTICA 2026-05-08
CVE-2026-6973 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authen… ALTA 2026-05-07
CVE-2026-0300 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Capti… CRÍTICA 2026-05-06
CVE-2026-31431 Linux Kernel Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escal… ALTA 2026-05-01
CVE-2026-41940 WebPros cPanel & WHM and WP2 (WordPress Squared) WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in th… CRÍTICA 2026-04-30
CVE-2024-1708 ConnectWise ScreenConnect ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code … ALTA 2026-04-28
CVE-2026-32202 Microsoft Windows Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to p… MEDIA 2026-04-28
CVE-2025-29635 D-Link DIR-823X D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary comm… ALTA 2026-04-24
CVE-2024-7399 Samsung MagicINFO 9 Server Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary file… ALTA 2026-04-24
← Anterior Página 3 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·