// THREAT RADAR

📡 Las CVE más peligrosas ahora mismo

Un ranking que se actualiza solo cruzando tres señales: si se está explotando activamente (CISA KEV), la probabilidad de explotación (EPSS) y la severidad (CVSS). No es "lo último publicado", es lo que de verdad importa priorizar.

En el radar40
Explotadas (KEV)40
Actualizadohace 10 min
🎯 Cómo se ordena: puntuación = EPSS + CVSS + KEV + frescura. El badge KEV marca explotación activa confirmada por CISA. Cada CVE enlaza a su ficha en NVD y a tus herramientas de CVSS y priorización de parches.

📡 Suscríbete por RSS · 🧩 Incrusta el «CVE del día» en tu web · 🌉 Convierte una CVE en detección

Filtro
#1
CVE-2026-8037 Crítica 9.6 Explotada (KEV)
Progress LoadMaster
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endp…
99%EPSS
9.6CVSS
#2
CVE-2026-63030 Crítica 9.8 Explotada (KEV)
WordPress Core
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Inje…
96%EPSS
9.8CVSS
#3
CVE-2026-48282 Crítica 10.0 Explotada (KEV)
Adobe ColdFusion
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user.…
99%EPSS
10.0CVSS
#4
CVE-2026-10520 Crítica 10.0 Explotada (KEV)
Ivanti Sentry
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
100%EPSS
10.0CVSS
#5
CVE-2026-39808 Crítica 9.8 Explotada (KEV)
Fortinet FortiSandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
91%EPSS
9.8CVSS
#6
CVE-2026-33824 Crítica 9.8 Explotada (KEV)
Microsoft Internet Key Exchange (IKE) Service Extensions
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
78%EPSS
9.8CVSS
#7
CVE-2008-4250 Crítica 9.8 Explotada (KEV)
n/a n/a
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overfl…
99%EPSS
9.8CVSS
#8
CVE-2026-20253 Crítica 9.8 Explotada (KEV)
Splunk Enterprise
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL s…
97%EPSS
9.8CVSS
#9
CVE-2026-48908 Crítica 10.0 Explotada (KEV)
JoomShaper SP Page Builder
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
88%EPSS
10.0CVSS
#10
CVE-2026-35273 Crítica 9.8 Explotada (KEV) Ransomware
Oracle PeopleSoft Enterprise PeopleTools
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticate…
95%EPSS
9.8CVSS
#11
CVE-2026-41940 Crítica 9.3 Explotada (KEV) Ransomware
WebPros cPanel & WHM and WP2 (WordPress Squared)
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
98%EPSS
9.3CVSS
#12
CVE-2026-39987 Crítica 9.3 Explotada (KEV)
Marimo Marimo
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell a…
97%EPSS
9.3CVSS
#13
CVE-2026-20182 Crítica 10.0 Explotada (KEV)
Cisco Catalyst SD-WAN
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection ha…
92%EPSS
10.0CVSS
#14
CVE-2026-48939 Crítica 10.0 Explotada (KEV)
iCagenda iCagenda
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
83%EPSS
10.0CVSS
#15
CVE-2026-56290 Crítica 10.0 Explotada (KEV)
Joomlack Page Builder
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and l…
83%EPSS
10.0CVSS
#16
CVE-2026-34910 Crítica 10.0 Explotada (KEV)
Ubiquiti UniFi OS
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
87%EPSS
10.0CVSS
#17
CVE-2026-50522 Crítica 9.8 Explotada (KEV)
Microsoft Microsoft SharePoint Enterprise Server 2016
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
77%EPSS
9.8CVSS
#18
CVE-2026-9082 Crítica 9.8 Explotada (KEV)
Drupal Core
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6…
88%EPSS
9.8CVSS
#19
CVE-2026-34908 Crítica 10.0 Explotada (KEV)
Ubiquiti Inc UniFi OS Server
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
85%EPSS
10.0CVSS
#20
CVE-2026-31431 Alta 7.8 Explotada (KEV)
Linux Linux
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operati…
100%EPSS
7.8CVSS
#21
CVE-2026-42208 Crítica 9.3 Explotada (KEV)
BerriAI LiteLLM
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text…
89%EPSS
9.3CVSS
#22
CVE-2024-7399 Alta 8.8 Explotada (KEV)
Samsung MagicINFO 9 Server
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
92%EPSS
8.8CVSS
#23
CVE-2010-0249 Alta 8.8 Explotada (KEV)
n/a n/a
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 all…
92%EPSS
8.8CVSS
#24
CVE-2026-56291 Crítica 10.0 Explotada (KEV)
balbooa.com balbooa.com Balbooa Forms extension for Joomla
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads…
76%EPSS
10.0CVSS
#25
CVE-2026-15409 Crítica 10.0 Explotada (KEV) Ransomware
SonicWall SMA1000
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
74%EPSS
10.0CVSS
#26
CVE-2026-34486 Alta 7.5 Explotada (KEV)
Apache Tomcat
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgr…
83%EPSS
7.5CVSS
#27
CVE-2026-25089 Crítica 9.8 Explotada (KEV)
Fortinet FortiSandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.…
74%EPSS
9.8CVSS
#28
CVE-2026-16232 Crítica 9.3 Explotada (KEV)
Check Point SmartConsole
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful…
73%EPSS
9.3CVSS
#29
CVE-2025-34291 Crítica 9.4 Explotada (KEV)
Langflow Langflow
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a re…
84%EPSS
9.4CVSS
#30
CVE-2026-0257 Alta 7.8 Explotada (KEV) Ransomware
Palo Alto Networks PAN-OS
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW…
94%EPSS
7.8CVSS
#31
CVE-2009-3459 Alta 8.8 Explotada (KEV)
n/a n/a
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wil…
87%EPSS
8.8CVSS
#32
CVE-2026-50751 Crítica 9.3 Explotada (KEV) Ransomware
Check Point Security Gateway
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a…
83%EPSS
9.3CVSS
#33
CVE-2024-1708 Alta 8.4 Explotada (KEV) Ransomware
ConnectWise ScreenConnect
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
88%EPSS
8.4CVSS
#34
CVE-2026-20230 Alta 8.6 Explotada (KEV)
Cisco Unified Communications Manager
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forger…
83%EPSS
8.6CVSS
#35
CVE-2026-42271 Alta 8.7 Explotada (KEV)
BerriAI LiteLLM
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp…
83%EPSS
8.7CVSS
#36
CVE-2010-0806 Alta 8.8 Explotada (KEV)
Microsoft Internet Explorer
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the dele…
82%EPSS
8.8CVSS
#37
CVE-2025-29635 Alta 7.2 Explotada (KEV)
n/a n/a
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, trigg…
90%EPSS
7.2CVSS
#38
CVE-2026-15410 Alta 7.2 Explotada (KEV) Ransomware
SonicWall SMA1000 Appliances
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated…
76%EPSS
7.2CVSS
#39
CVE-2026-42897 Alta 8.1 Explotada (KEV)
Microsoft Microsoft Exchange Server 2016 Cumulative Update 23
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
70%EPSS
8.1CVSS
#40
CVE-2026-60137 Media 5.9 Explotada (KEV)
WordPress Core
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
73%EPSS
5.9CVSS

Fuentes: CISA KEV · EPSS · FIRST.org · CIRCL · NVD. Datos meramente informativos; contrasta siempre con la fuente oficial del fabricante.