// THREAT RADAR

📡 Las CVE más peligrosas ahora mismo

Un ranking que se actualiza solo cruzando tres señales: si se está explotando activamente (CISA KEV), la probabilidad de explotación (EPSS) y la severidad (CVSS). No es "lo último publicado", es lo que de verdad importa priorizar.

En el radar40
Explotadas (KEV)33
Actualizadohace 10 h
🎯 Cómo se ordena: puntuación = EPSS + CVSS + KEV + frescura. El badge KEV marca explotación activa confirmada por CISA. Cada CVE enlaza a su ficha en NVD y a tus herramientas de CVSS y priorización de parches.

📡 Suscríbete por RSS · 🧩 Incrusta el «CVE del día» en tu web · 🌉 Convierte una CVE en detección

Filtro
#1
CVE-2026-8037 Crítica 9.6 Explotada (KEV)
Progress LoadMaster
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endp…
99%EPSS
9.6CVSS
#2
CVE-2026-63030 Crítica 9.8 Explotada (KEV)
WordPress Core
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Inje…
96%EPSS
9.8CVSS
#3
CVE-2026-48282 Crítica 10.0 Explotada (KEV)
Adobe ColdFusion
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user.…
99%EPSS
10.0CVSS
#4
CVE-2026-10520 Crítica 10.0 Explotada (KEV)
Ivanti Sentry
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
100%EPSS
10.0CVSS
#5
CVE-2026-39808 Crítica 9.8 Explotada (KEV)
Fortinet FortiSandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
91%EPSS
9.8CVSS
#6
CVE-2008-4250 Crítica 9.8 Explotada (KEV)
n/a n/a
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overfl…
99%EPSS
9.8CVSS
#7
CVE-2026-20253 Crítica 9.8 Explotada (KEV)
Splunk Enterprise
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL s…
97%EPSS
9.8CVSS
#8
CVE-2026-48908 Crítica 10.0 Explotada (KEV)
JoomShaper SP Page Builder
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
88%EPSS
10.0CVSS
#9
CVE-2026-35273 Crítica 9.8 Explotada (KEV) Ransomware
Oracle PeopleSoft Enterprise PeopleTools
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticate…
95%EPSS
9.8CVSS
#10
CVE-2026-41940 Crítica 9.3 Explotada (KEV) Ransomware
WebPros cPanel & WHM and WP2 (WordPress Squared)
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
98%EPSS
9.3CVSS
#11
CVE-2026-39987 Crítica 9.3 Explotada (KEV)
Marimo Marimo
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell a…
97%EPSS
9.3CVSS
#12
CVE-2026-20182 Crítica 10.0 Explotada (KEV)
Cisco Catalyst SD-WAN
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection ha…
92%EPSS
10.0CVSS
#13
CVE-2026-48939 Crítica 10.0 Explotada (KEV)
iCagenda iCagenda
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
83%EPSS
10.0CVSS
#14
CVE-2026-56290 Crítica 10.0 Explotada (KEV)
Joomlack Page Builder
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and l…
83%EPSS
10.0CVSS
#15
CVE-2026-34910 Crítica 10.0 Explotada (KEV)
Ubiquiti UniFi OS
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
87%EPSS
10.0CVSS
#16
CVE-2026-50522 Crítica 9.8 Explotada (KEV)
Microsoft Microsoft SharePoint Enterprise Server 2016
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
77%EPSS
9.8CVSS
#17
CVE-2026-9082 Crítica 9.8 Explotada (KEV)
Drupal Core
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6…
88%EPSS
9.8CVSS
#18
CVE-2026-34908 Crítica 10.0 Explotada (KEV)
Ubiquiti UniFi OS
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
85%EPSS
10.0CVSS
#19
CVE-2026-31431 Alta 7.8 Explotada (KEV)
Linux Linux
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operati…
100%EPSS
7.8CVSS
#20
CVE-2026-42208 Crítica 9.3 Explotada (KEV)
BerriAI LiteLLM
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text…
89%EPSS
9.3CVSS
#21
CVE-2024-7399 Alta 8.8 Explotada (KEV)
Samsung MagicINFO 9 Server
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
92%EPSS
8.8CVSS
#22
CVE-2010-0249 Alta 8.8 Explotada (KEV)
n/a n/a
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 all…
92%EPSS
8.8CVSS
#23
CVE-2026-56291 Crítica 10.0 Explotada (KEV)
Balbooa Forms
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads…
76%EPSS
10.0CVSS
#24
CVE-2026-34486 Alta 7.5 Explotada (KEV)
Apache Tomcat
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgr…
83%EPSS
7.5CVSS
#25
CVE-2026-16232 Crítica 9.3 Explotada (KEV)
Check Point SmartConsole
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful…
73%EPSS
9.3CVSS
#26
CVE-2025-34291 Crítica 9.4 Explotada (KEV)
Langflow Langflow
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a re…
84%EPSS
9.4CVSS
#27
CVE-2026-0257 Alta 7.8 Explotada (KEV) Ransomware
Palo Alto Networks PAN-OS
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW…
94%EPSS
7.8CVSS
#28
CVE-2009-3459 Alta 8.8 Explotada (KEV)
n/a n/a
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wil…
87%EPSS
8.8CVSS
#29
CVE-2024-1708 Alta 8.4 Explotada (KEV) Ransomware
ConnectWise ScreenConnect
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
88%EPSS
8.4CVSS
#30
CVE-2026-20230 Alta 8.6 Explotada (KEV)
Cisco Cisco Unified Communications Manager
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forger…
83%EPSS
8.6CVSS
#31
CVE-2025-29635 Alta 7.2 Explotada (KEV)
n/a n/a
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, trigg…
90%EPSS
7.2CVSS
#32
CVE-2024-3400 Crítica 10.0
Palo Alto Networks PAN-OS
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated atta…
100%EPSS
10.0CVSS
#33
CVE-2023-22518 Crítica 10.0
Atlassian Confluence Data Center
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrat…
100%EPSS
10.0CVSS
#34
CVE-2026-15410 Alta 7.2 Explotada (KEV) Ransomware
SonicWall SMA1000
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated…
76%EPSS
7.2CVSS
#35
CVE-2023-27350 Crítica 9.8
PaperCut NG
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompl…
100%EPSS
9.8CVSS
#36
CVE-2023-1671 Crítica 9.8
Sophos Sophos Web Appliance
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
100%EPSS
9.8CVSS
#37
CVE-2022-29464 Crítica 9.8
n/a n/a
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such a…
100%EPSS
9.8CVSS
#38
CVE-2024-21887 Crítica 9.1
Ivanti ICS
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the ap…
100%EPSS
9.1CVSS
#39
CVE-2026-60137 Media 5.9 Explotada (KEV)
WordPress Core
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
73%EPSS
5.9CVSS
#40
CVE-2024-21893 Alta 8.2
Ivanti ICS
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authen…
100%EPSS
8.2CVSS

Fuentes: CISA KEV · EPSS · FIRST.org · CIRCL · NVD. Datos meramente informativos; contrasta siempre con la fuente oficial del fabricante.