CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2026-24423 SmarterTools SmarterMail SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API … CRÍTICA 2026-02-05
CVE-2021-39935 GitLab Community and Enterprise Editions GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthor… MEDIA 2026-02-03
CVE-2025-64328 Sangoma FreePBX Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authenticat… ALTA 2026-02-03
CVE-2019-19006 Sangoma FreePBX Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass … CRÍTICA 2026-02-03
CVE-2025-40551 SolarWinds Web Help Desk SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code exec… CRÍTICA 2026-02-03
CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve una… CRÍTICA 2026-01-29
CVE-2026-24858 Fortinet Multiple Products Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path … CRÍTICA 2026-01-27
CVE-2018-14634 Linux Kernel Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unpriv… ALTA 2026-01-26
CVE-2025-52691 SmarterTools SmarterMail SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an … CRÍTICA 2026-01-26
CVE-2026-23760 SmarterTools SmarterMail SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the pass… CRÍTICA 2026-01-26
CVE-2026-24061 GNU InetUtils GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass… CRÍTICA 2026-01-26
CVE-2026-21509 Microsoft Office Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security d… ALTA 2026-01-26
CVE-2024-37079 Broadcom VMware vCenter Server Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protoc… CRÍTICA 2026-01-23
CVE-2025-68645 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote… ALTA 2026-01-22
CVE-2025-34026 Versa Concerto Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse p… ALTA 2026-01-22
CVE-2025-31125 Vite Vitejs Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&i… MEDIA 2026-01-22
CVE-2025-54313 Prettier eslint-config-prettier Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package execu… ALTA 2026-01-22
CVE-2026-20045 Cisco Unified Communications Manager Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Uni… ALTA 2026-01-21
CVE-2026-20805 Microsoft Windows Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized at… MEDIA 2026-01-13
CVE-2025-8110 Gogs Gogs Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that coul… ALTA 2026-01-12
CVE-2009-0556 Microsoft Office Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary c… ALTA 2026-01-07
CVE-2025-37164 Hewlett Packard Enterprise (HPE) OneView Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated u… CRÍTICA 2026-01-07
CVE-2025-14847 MongoDB MongoDB and MongoDB Server MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protoco… ALTA 2025-12-29
CVE-2023-52163 Digiever DS-2105 Pro Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tz… ALTA 2025-12-22
CVE-2025-14733 WatchGuard Firebox WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerab… CRÍTICA 2025-12-19
← Anterior Página 7 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·