CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2026-22719 Broadcom VMware Aria Operations Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerabilit… ALTA 2026-03-03
CVE-2026-21385 Qualcomm Multiple Chipsets Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. ALTA 2026-03-03
CVE-2022-20775 Cisco SD-WAN Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain eleva… ALTA 2026-02-25
CVE-2026-20127 Cisco Catalyst SD-WAN Controller and Manager Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, c… CRÍTICA 2026-02-25
CVE-2026-25108 Soliton Systems K.K FileZen Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product… ALTA 2026-02-24
CVE-2025-49113 Roundcube Webmail RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authe… CRÍTICA 2026-02-20
CVE-2025-68461 Roundcube Webmail RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. ALTA 2026-02-20
CVE-2021-22175 GitLab GitLab GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks a… MEDIA 2026-02-18
CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allo… CRÍTICA 2026-02-18
CVE-2020-7796 Synacor Zimbra Collaboration Suite Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed… CRÍTICA 2026-02-17
CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSon… ALTA 2026-02-17
CVE-2008-0015 Microsoft Windows Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the v… ALTA 2026-02-17
CVE-2026-2441 Google Chromium Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit h… ALTA 2026-02-17
CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Succes… CRÍTICA 2026-02-13
CVE-2026-20700 Apple Multiple Products Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memo… ALTA 2026-02-12
CVE-2024-43468 Microsoft Configuration Manager Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this… CRÍTICA 2026-02-12
CVE-2025-15556 Notepad++ Notepad++ Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could a… ALTA 2026-02-12
CVE-2025-40536 SolarWinds Web Help Desk SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker … ALTA 2026-02-12
CVE-2026-21513 Microsoft Windows Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attac… ALTA 2026-02-10
CVE-2026-21525 Microsoft Windows Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized… MEDIA 2026-02-10
CVE-2026-21510 Microsoft Windows Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker… ALTA 2026-02-10
CVE-2026-21533 Microsoft Windows Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an a… ALTA 2026-02-10
CVE-2026-21519 Microsoft Windows Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to el… ALTA 2026-02-10
CVE-2026-21514 Microsoft Office Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an … ALTA 2026-02-10
CVE-2025-11953 React Native Community CLI React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network att… CRÍTICA 2026-02-05
← Anterior Página 6 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·