Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.58% | — | Fortinet Fortiauthenticator | 9/12/2021 | 17/6/2026 | A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal. | |
| Modificada | Media (6.5) | 1.1% | — | Fortinet Fortiauthenticator | 8/12/2021 | 17/6/2026 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP user 2 factors authentication token via crafted HTTP requests. | |
| Modificada | Crítica (9.8) | 1.4% | — | Jupyterhub First USE Authenticator | 28/10/2021 | 17/6/2026 | FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if `create_users=True` and the username is… | |
| Modificada | Alta (7.5) | 1.0% | — | Fortinet FortiauthenticatorFortinet Fortisandbox | 4/8/2021 | 17/6/2026 | An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via… | |
| Modificada | Alta (7.5) | 0.56% | — | Fortinet Fortiauthenticator | 6/7/2021 | 17/6/2026 | Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key. | |
| Modificada | Media (6.3) | 1.1% | — | Jupyter Oauthenticator | 1/12/2020 | 17/6/2026 | OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which should be transparently mapped to `Authenticator.allowed_users` with a warning, is instead ignored by OAuthenticator… | |
| Modificada | Media (6.1) | 0.70% | — | Fortinet Fortiauthenticator | 7/1/2020 | 17/6/2026 | An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page. | |
| Modificada | Media (6.1) | 0.75% | — | Fortinet Fortiauthenticator | 31/5/2018 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header. | |
| Modificada | Alta (8.8) | 1.8% | — | Jupyter Oauthenticator | 18/2/2018 | 17/6/2026 | An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were… | |
| Modificada | Media (6.1) | 1.0% | — | Falconsc WisepointFalconsc Wisepoint Authenticator | 5/4/2016 | 17/6/2026 | The management screen in Falcon WisePoint 4.3.1 and earlier and WisePoint Authenticator 4.1.19.22 and earlier allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Fortinet Fortiauthenticator | 3/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/. | |
| Modificada | Media (6.9) | 0.45% | — | Fortinet Fortiauthenticator | 3/2/2015 | 17/6/2026 | Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "shell" command. | |
| Modificada | Media (4.9) | 0.49% | — | Fortinet Fortiauthenticator | 3/2/2015 | 17/6/2026 | Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command. | |
| Modificada | Media (4) | 1.4% | — | Fortinet Fortiauthenticator | 3/2/2015 | 17/6/2026 | Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/. | |
| Modificada | Alta (7.5) | 2.7% | — | Fortinet Fortiauthenticator | 3/2/2015 | 17/6/2026 | Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | Google Authenticator Login Project GA Login | 29/5/2014 | 16/6/2026 | The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP). | |
| Modificada | Media (5) | 1.4% | — | Google Authenticator Login Project GA Login | 29/5/2014 | 16/6/2026 | The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors. | |
| Modificada | Alta (9) | 1.1% | — | Fortinet Fortiauthenticator | 30/4/2014 | 17/6/2026 | FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface. | |
| Modificada | Baja (1.9) | 0.23% | — | Google Authenticator | 24/4/2013 | 16/6/2026 | pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258. | |
| Modificada | Media (6.8) | 1.4% | — | Google Authenticator Login Project GA Login | 27/3/2013 | 16/6/2026 | The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username. |