CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

1
CVEs añadidos este mes
1587
Total KEV catalogados
10
Vendors afectados
CVE Producto Criticidad Añadido
CVE-2026-31431 Linux Kernel ALTA 2026-05-01
Microsoft
19
Cisco
7
Apple
7
Synacor
4
Google
4
Fortinet
3
Ivanti
3
SolarWinds
3
SmarterTools
3
Linux
2
CVE ID Producto Descripción CVSS Añadido
CVE-2021-27860 FatPipe WARP, IPVPN, and MPVPN software A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthentic… CRÍTICA 2022-01-10
CVE-2021-43890 Microsoft Windows Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integri… ALTA 2021-12-15
CVE-2021-4102 Google Chromium V8 Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit … ALTA 2021-12-15
CVE-2021-44515 Zoho Desktop Central Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary … CRÍTICA 2021-12-10
CVE-2019-13272 Linux Kernel Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local us… ALTA 2021-12-10
CVE-2021-35394 Realtek Jungle Software Development Kit (SDK) RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote co… CRÍTICA 2021-12-10
CVE-2019-7238 Sonatype Nexus Repository Manager Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for … CRÍTICA 2021-12-10
CVE-2019-0193 Apache Solr The optional Apache Solr module DataImportHandler contains a code injection vulnerability. ALTA 2021-12-10
CVE-2021-44168 Fortinet FortiOS Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrari… BAJA 2021-12-10
CVE-2017-17562 Embedthis GoAhead Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. ALTA 2021-12-10
CVE-2017-12149 Red Hat JBoss Application Server The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute a… CRÍTICA 2021-12-10
CVE-2010-1871 Red Hat JBoss Seam 2 JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers … ALTA 2021-12-10
CVE-2020-17463 Fuel CMS Fuel CMS FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. CRÍTICA 2021-12-10
CVE-2020-8816 Pi-hole AdminLTE Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static … ALTA 2021-12-10
CVE-2019-10758 MongoDB mongo-express mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. CRÍTICA 2021-12-10
CVE-2021-44228 Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endp… CRÍTICA 2021-12-10
CVE-2020-11261 Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Memory corruption due to improper check to return error when user application requests memory allocation of a huge size… ALTA 2021-12-01
CVE-2018-14847 MikroTik RouterOS MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated… CRÍTICA 2021-12-01
CVE-2021-37415 Zoho ManageEngine ServiceDesk Plus (SDP) Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs … CRÍTICA 2021-12-01
CVE-2021-40438 Apache Apache A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. T… CRÍTICA 2021-12-01
CVE-2021-44077 Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014… CRÍTICA 2021-12-01
CVE-2021-22204 Perl Exiftool Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code exe… MEDIA 2021-11-17
CVE-2021-40449 Microsoft Windows Unspecified vulnerability allows for an authenticated user to escalate privileges. ALTA 2021-11-17
CVE-2021-42321 Microsoft Exchange An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform … ALTA 2021-11-17
CVE-2021-42292 Microsoft Office A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. ALTA 2021-11-17
← Anterior Página 52 / 64 (1587 CVEs total) Siguiente →
[INFO] CVE-2026-31431: Vulnerabilidad de Escalada de Privilegios en Linux Kernel  ·  [INFO] CVE-2026-41940: Vulnerabilidad Crítica de Bypass de Autenticación en cPanel & WHM y WP2  ·  [INFO] CVE-2024-1708: Path Traversal en ConnectWise ScreenConnect Explotado Activamente  ·  [INFO] CVE-2026-32202: Fallo en Mecanismo de Protección en Microsoft Windows  ·  [INFO] CVE-2024-57726: Vulnerabilidad Crítica de Autorización en SimpleHelp  ·  [INFO] CVE-2026-31431: Vulnerabilidad de Escalada de Privilegios en Linux Kernel  ·  [INFO] CVE-2026-41940: Vulnerabilidad Crítica de Bypass de Autenticación en cPanel & WHM y WP2  ·  [INFO] CVE-2024-1708: Path Traversal en ConnectWise ScreenConnect Explotado Activamente  ·  [INFO] CVE-2026-32202: Fallo en Mecanismo de Protección en Microsoft Windows  ·  [INFO] CVE-2024-57726: Vulnerabilidad Crítica de Autorización en SimpleHelp  ·