CIBERPLANETA_
// threat_intelligence_dashboard

Dashboard de Amenazas

Vulnerabilidades activamente explotadas según el catálogo CISA KEV (Known Exploited Vulnerabilities)

¿Cómo se calcula el nivel de amenaza global?

El nivel de amenaza global mostrado en la barra de navegación se calcula en base al número de CVEs activamente explotados publicados en el catálogo CISA KEV (Known Exploited Vulnerabilities) durante las últimas horas:

  • 🟢 BAJA — 0 CVEs nuevos en el feed reciente
  • 🟡 MEDIA — 1 a 2 CVEs nuevos activamente explotados
  • 🟠 ALTA — 3 a 4 CVEs nuevos activamente explotados
  • 🔴 CRÍTICA — 5 o más CVEs nuevos activamente explotados

Fuente: CISA Known Exploited Vulnerabilities Catalog — actualizado cada hora.

0
CVEs añadidos este mes
1656
Total KEV catalogados
10
Vendors afectados
Microsoft
20
Cisco
9
Fortinet
5
Adobe
4
Langflow
3
Oracle
3
SimpleHelp
3
Ubiquiti
3
Ivanti
3
Arista
2
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
The Hacker News · 01 Ago 2026 ↗
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
The Hacker News · 01 Ago 2026 ↗
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
The Hacker News · 01 Ago 2026 ↗
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
The Hacker News · 01 Ago 2026 ↗
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
The Hacker News · 31 Jul 2026 ↗
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
The Hacker News · 31 Jul 2026 ↗
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
The Hacker News · 31 Jul 2026 ↗
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
The Hacker News · 31 Jul 2026 ↗
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
The Hacker News · 31 Jul 2026 ↗
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
The Hacker News · 31 Jul 2026 ↗
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
The Hacker News · 31 Jul 2026 ↗
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
The Hacker News · 31 Jul 2026 ↗
CVE ID Producto Descripción CVSS Añadido
CVE-2025-21042 Samsung Mobile Devices Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could… ALTA 2025-11-10
CVE-2025-48703 CWP Control Web Panel CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenti… CRÍTICA 2025-11-04
CVE-2025-11371 Gladinet CentreStack and Triofox Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allo… ALTA 2025-11-04
CVE-2025-41244 Broadcom VMware Aria Operations and VMware Tools Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malic… ALTA 2025-10-30
CVE-2025-24893 XWiki Platform XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code exe… CRÍTICA 2025-10-30
CVE-2025-6204 Dassault Systèmes DELMIA Apriso Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitra… ALTA 2025-10-28
CVE-2025-6205 Dassault Systèmes DELMIA Apriso Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain pri… CRÍTICA 2025-10-28
CVE-2025-54236 Adobe Commerce and Magento Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker … CRÍTICA 2025-10-24
CVE-2025-59287 Microsoft Windows Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows f… CRÍTICA 2025-10-24
CVE-2025-61932 Motex LANSCOPE Endpoint Manager Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability al… CRÍTICA 2025-10-22
CVE-2022-48503 Apple Multiple Products Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing… ALTA 2025-10-20
CVE-2025-2746 Kentico Xperience CMS Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could all… CRÍTICA 2025-10-20
CVE-2025-2747 Kentico Xperience CMS Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could all… CRÍTICA 2025-10-20
CVE-2025-33073 Microsoft Windows Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalatio… ALTA 2025-10-20
CVE-2025-61884 Oracle E-Business Suite Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle … ALTA 2025-10-20
CVE-2025-54253 Adobe Experience Manager (AEM) Forms Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. CRÍTICA 2025-10-15
CVE-2025-47827 IGEL IGEL OS IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-fla… MEDIA 2025-10-14
CVE-2025-24990 Microsoft Windows Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege … ALTA 2025-10-14
CVE-2025-59230 Microsoft Windows Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which c… ALTA 2025-10-14
CVE-2016-7836 SKYSEA Client View SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in pr… CRÍTICA 2025-10-14
CVE-2021-43798 Grafana Labs Grafana Grafana contains a path traversal vulnerability that could allow access to local files. ALTA 2025-10-09
CVE-2025-27915 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web C… MEDIA 2025-10-07
CVE-2021-22555 Linux Kernel Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause… ALTA 2025-10-06
CVE-2010-3962 Microsoft Internet Explorer Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code … ALTA 2025-10-06
CVE-2021-43226 Microsoft Windows Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local,… ALTA 2025-10-06
← Anterior Página 9 / 67 (1656 CVEs total) Siguiente →
[INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·  [INFO] CVE-2026-20316: Contraseña Hardcoded en Cisco Secure Firewall Management Center Activamente Explotada  ·  [INFO] CVE-2026-16812: Inyección de Comandos OS Crítica en Arista VeloCloud Orchestrator Explotada Activamente  ·  [INFO] CVE-2025-68686: Fortinet FortiOS expone información sensible y permite evasión de parches de seguridad  ·  [INFO] CVE-2026-16232: Vulnerabilidad crítica de autenticación en Check Point SmartConsole explotada activamente  ·  [INFO] CVE-2026-50522: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Explotada Activamente  ·