CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

13
CVEs añadidos este mes
1542
Total KEV catalogados
10
Vendors afectados
CVE Producto Criticidad Añadido
CVE-2026-3910 Google Chromium V8 ALTA 2026-03-13
CVE-2026-3909 Google Skia ALTA 2026-03-13
CVE-2025-68613 n8n n8n CRÍTICA 2026-03-11
CVE-2021-22054 Omnissa Workspace One UEM ALTA 2026-03-09
CVE-2025-26399 SolarWinds Web Help Desk CRÍTICA 2026-03-09
CVE-2026-1603 Ivanti Endpoint Manager (EPM) ALTA 2026-03-09
CVE-2017-7921 Hikvision Multiple Products CRÍTICA 2026-03-05
CVE-2021-22681 Rockwell Multiple Products CRÍTICA 2026-03-05
CVE-2023-43000 Apple Multiple Products ALTA 2026-03-05
CVE-2021-30952 Apple Multiple Products ALTA 2026-03-05
Microsoft
15
Apple
6
Google
5
Cisco
4
Fortinet
4
SolarWinds
3
Broadcom
3
SmarterTools
3
Gladinet
3
Ivanti
2
CVE ID Producto Descripción CVSS Añadido
CVE-2025-34026 Versa Concerto Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse p… ALTA 2026-01-22
CVE-2025-31125 Vite Vitejs Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&i… MEDIA 2026-01-22
CVE-2025-54313 Prettier eslint-config-prettier Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package execu… ALTA 2026-01-22
CVE-2026-20045 Cisco Unified Communications Manager Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Uni… ALTA 2026-01-21
CVE-2026-20805 Microsoft Windows Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized at… MEDIA 2026-01-13
CVE-2025-8110 Gogs Gogs Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that coul… ALTA 2026-01-12
CVE-2009-0556 Microsoft Office Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary c… ALTA 2026-01-07
CVE-2025-37164 Hewlett Packard Enterprise (HPE) OneView Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated u… CRÍTICA 2026-01-07
CVE-2025-14847 MongoDB MongoDB and MongoDB Server MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protoco… ALTA 2025-12-29
CVE-2023-52163 Digiever DS-2105 Pro Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tz… 2025-12-22
CVE-2025-14733 WatchGuard Firebox WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerab… 2025-12-19
CVE-2025-59374 ASUS Live Update ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modificati… 2025-12-17
CVE-2025-40602 SonicWall SMA1000 appliance SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance ma… 2025-12-17
CVE-2025-20393 Cisco Multiple Products Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input valid… 2025-12-17
CVE-2025-59718 Fortinet Multiple Products Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signatu… 2025-12-16
CVE-2025-14611 Gladinet CentreStack and Triofox Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the A… 2025-12-15
CVE-2025-43529 Apple Multiple Products Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing malicio… 2025-12-15
CVE-2018-4063 Sierra Wireless AirLink ALEOS Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially cr… 2025-12-12
CVE-2025-14174 Google Chromium Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to pe… 2025-12-12
CVE-2025-58360 OSGeo GeoServer OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the ap… 2025-12-11
CVE-2025-6218 RARLAB WinRAR RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the curren… 2025-12-09
CVE-2025-62221 Microsoft Windows Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized a… 2025-12-09
CVE-2022-37055 D-Link Routers D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and avail… 2025-12-08
CVE-2025-66644 Array Networks ArrayOS AG Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitr… 2025-12-08
CVE-2025-55182 Meta React Server Components Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote cod… 2025-12-05
← Anterior Página 3 / 62 (1542 CVEs total) Siguiente →
[INFO] CVE-2021-30952: Desbordamiento Entero en Productos Apple Explotado Activamente  ·  [INFO] CVE-2023-43000: Vulnerabilidad Use-After-Free en Productos Apple Explotada  ·  [INFO] CVE-2021-22681: Vulnerabilidad Crítica de Credenciales en Productos Rockwell  ·  [INFO] CVE-2017-7921: Vulnerabilidad Crítica de Autenticación en Productos Hikvision  ·  [INFO] CVE-2026-1603: Vulnerabilidad de Bypass de Autenticación en Ivanti Endpoint Manager  ·  [INFO] CVE-2021-30952: Desbordamiento Entero en Productos Apple Explotado Activamente  ·  [INFO] CVE-2023-43000: Vulnerabilidad Use-After-Free en Productos Apple Explotada  ·  [INFO] CVE-2021-22681: Vulnerabilidad Crítica de Credenciales en Productos Rockwell  ·  [INFO] CVE-2017-7921: Vulnerabilidad Crítica de Autenticación en Productos Hikvision  ·  [INFO] CVE-2026-1603: Vulnerabilidad de Bypass de Autenticación en Ivanti Endpoint Manager  ·