CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2025-59374 ASUS Live Update ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modificati… CRÍTICA 2025-12-17
CVE-2025-40602 SonicWall SMA1000 appliance SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance ma… MEDIA 2025-12-17
CVE-2025-20393 Cisco Multiple Products Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input valid… CRÍTICA 2025-12-17
CVE-2025-59718 Fortinet Multiple Products Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signatu… CRÍTICA 2025-12-16
CVE-2025-14611 Gladinet CentreStack and Triofox Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the A… CRÍTICA 2025-12-15
CVE-2025-43529 Apple Multiple Products Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing malicio… ALTA 2025-12-15
CVE-2018-4063 Sierra Wireless AirLink ALEOS Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially cr… ALTA 2025-12-12
CVE-2025-14174 Google Chromium Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to pe… ALTA 2025-12-12
CVE-2025-58360 OSGeo GeoServer OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the ap… ALTA 2025-12-11
CVE-2025-6218 RARLAB WinRAR RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the curren… ALTA 2025-12-09
CVE-2025-62221 Microsoft Windows Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized a… ALTA 2025-12-09
CVE-2022-37055 D-Link Routers D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and avail… CRÍTICA 2025-12-08
CVE-2025-66644 Array Networks ArrayOS AG Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitr… ALTA 2025-12-08
CVE-2025-55182 Meta React Server Components Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote cod… CRÍTICA 2025-12-05
CVE-2021-26828 OpenPLC ScadaBR OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authentica… ALTA 2025-12-03
CVE-2025-48633 Android Framework Android Framework contains an unspecified vulnerability that allows for information disclosure. MEDIA 2025-12-02
CVE-2025-48572 Android Framework Android Framework contains an unspecified vulnerability that allows for privilege escalation. ALTA 2025-12-02
CVE-2021-26829 OpenPLC ScadaBR OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm. MEDIA 2025-11-28
CVE-2025-61757 Oracle Fusion Middleware Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticate… CRÍTICA 2025-11-21
CVE-2025-13223 Google Chromium V8 Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. ALTA 2025-11-19
CVE-2025-58034 Fortinet FortiWeb Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute un… ALTA 2025-11-18
CVE-2025-64446 Fortinet FortiWeb Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execut… CRÍTICA 2025-11-14
CVE-2025-12480 Gladinet Triofox Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after… CRÍTICA 2025-11-12
CVE-2025-62215 Microsoft Windows Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges… ALTA 2025-11-12
CVE-2025-9242 WatchGuard Firebox WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthe… CRÍTICA 2025-11-12
← Anterior Página 8 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·