Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.35%—Fortinet Fortiauthenticator3/6/202417/6/2026
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
AnalizadaCrítica (9.1)0.59%—Jupyter Oauthenticator20/3/202417/6/2026
OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. `GoogleOAuthenticator.hosted_domain` is used to restrict what Google accounts can be authorized access to a JupyterHub. The restriction is intented to…
ModificadaAlta (7.1)1.3%—Microsoft Authenticator12/3/202417/6/2026
Microsoft Authenticator Elevation of Privilege Vulnerability
ModificadaAlta (7.5)0.70%—Miniorange Google Authenticator29/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login.This issue affects miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA ,…
ModificadaMedia (6.5)1.2%—Michaelkelly Duouniversalkeycloakauthenticator23/12/202317/6/2026
An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this…
ModificadaMedia (5.3)0.54%—Miniorange Google Authenticator20/10/202317/6/2026
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.
ModificadaBaja (3.3)0.29%—Fortinet FortiauthenticatorFortinet Fortios11/7/202317/6/2026
A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to…
ModificadaAlta (8.8)0.62%—Hypr Keycloak Authenticator28/4/202317/6/2026
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.
ModificadaMedia (6.1)0.49%—Fortinet Fortiauthenticator11/4/202317/6/2026
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password"…
ModificadaMedia (6.5)0.40%—SAP Authenticator14/3/202317/6/2026
SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device. The attacker could extract the currently views of the OTP and the secret OTP alphanumeric token during the token setup. On successful exploitation, an attacker can…
ModificadaMedia (5.3)1.8%—Fortinet Fortiauthenticator9/3/202317/6/2026
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
ModificadaCrítica (9.8)0.68%—Authenticator Plugin Project Authenticator Plugin17/1/202316/6/2026
A vulnerability was found in Bricco Authenticator Plugin. It has been declared as critical. This vulnerability affects the function authenticate/compare of the file src/java/talentum/escenic/plugins/authenticator/authenticators/DBAuthenticator.java. The manipulation leads to sql injection. Upgrading to version 1.39 is…
ModificadaMedia (4.3)0.77%—Authenticator Project Authenticator2/1/202317/6/2026
The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may deny other users access to the functionality in certain configurations.
ModificadaAlta (8.8)0.69%—Miniorange Google Authenticator18/11/202217/6/2026
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
ModificadaAlta (7.5)0.79%—SAP Authenticator10/8/202217/6/2026
Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.
ModificadaMedia (6.1)0.58%—Fortinet Fortiauthenticator Agent FOR Microsoft Outlook WEB Access18/7/202217/6/2026
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
ModificadaAlta (8.8)1.1%—Kubernetes Aws-iam-authenticator12/7/202217/6/2026
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
ModificadaMedia (4.8)0.59%—Miniorange Login With OTP Over Sms, Email, Whatsapp AND Google Authenticator27/6/202217/6/2026
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
ModificadaMedia (4.8)0.59%—Miniorange Google Authenticator27/6/202217/6/2026
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
ModificadaMedia (4.3)0.43%—Miniorange Google Authenticator27/6/202217/6/2026
The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
ModificadaMedia (6.5)0.47%—Jupyter Oauthenticator9/6/202217/6/2026
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of…
ModificadaBaja (3.9)0.23%—Sophos AuthenticatorSophos Intercept X27/4/202217/6/2026
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
ModificadaAlta (8.8)0.62%—Fortinet Fortiauthenticator6/4/202217/6/2026
An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
ModificadaAlta (8.1)0.55%—Miniorange Google Authenticator21/3/202217/6/2026
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.
ModificadaMedia (4.3)0.30%—Fortinet Fortiauthenticator2/2/202217/6/2026
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.