Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.44%—Microsoft Authenticator8/9/202624/9/2026
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
AplazadaBaja (1.9)0.15%—Extension.vn 2FA Authenticator ExtensionAI31/8/20262/9/2026
A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service Worker. Executing a manipulation of the argument sender.id can lead to information disclosure. The attack…
AplazadaMedia (6.5)0.18%—Miniorange Google AuthenticatorAI6/8/202626/8/2026
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.
AnalizadaAlta (7.5)0.53%—Fortinet Fortiauthenticator14/7/202629/9/2026
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
AnalizadaAlta (7.4)1.1%—Microsoft Authenticator14/5/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.
ModificadaCrítica (9.8)0.48%—Fortinet Fortiauthenticator12/5/202617/6/2026
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.
AnalizadaMedia (5.9)0.41%—LTI Jupyterhub Authenticator3/4/202624/7/2026
LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests…
AnalizadaAlta (8.8)0.64%—Jupyter Oauthenticator3/4/202624/7/2026
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the…
ModificadaCrítica (9.3)0.47%—Gematik Authenticator27/3/202617/6/2026
Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to…
ModificadaAlta (7.8)0.30%—Gematik Authenticator27/3/202617/6/2026
Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authenticator to version…
AnalizadaMedia (5.5)0.54%—Microsoft Authenticator10/3/202617/6/2026
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.2)0.36%—Fortinet Fortiauthenticator10/2/202617/6/2026
A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected endpoint.
ModificadaBaja (2.7)0.21%—Fortinet Fortiauthenticator9/12/202517/6/2026
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other…
AnalizadaBaja (2.7)0.23%—Fortinet Fortiauthenticator9/12/202530/9/2026
A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via…
AplazadaAlta (7.2)0.15%—Netknights Gmbh Privacyidea AuthenticatorAI27/10/202517/6/2026
Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of…
AnalizadaAlta (8.8)0.35%—Authenticator Login Project Authenticator Login10/10/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.
AnalizadaMedia (6.9)0.22%—Qnap Authenticator3/10/202517/6/2026
An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP Authenticator 1.3.1.1227 and later
AnalizadaCrítica (9.8)0.52%—Authenticator Login Project Authenticator Login15/8/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4.
AnalizadaCrítica (9.8)0.42%—Authenticator Login Project Authenticator Login31/3/202517/6/2026
Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6.
AnalizadaCrítica (9.8)0.36%—LTI Jupyterhub Authenticator25/2/202517/6/2026
`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has…
AplazadaMedia (4)0.14%—Nitrokey 3 FirmwareAIPIV AuthenticatorAI12/2/202517/6/2026
Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for authentication of the admin key. This could lead to compromise of the integrity of the data stored in the application. An attacker…
ModificadaMedia (6.1)0.45%—Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+1022/1/202517/6/2026
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
ModificadaAlta (7.8)0.09%—Authenticator3/9/202417/6/2026
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key.…
AnalizadaMedia (5.3)1.7%⚠ Explotación activaTwilio AuthyTwilio Authy Authenticator2/7/202417/6/2026
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with…
AplazadaAlta (8.1)0.40%—JupyterhubAIJupyter OauthenticatorAI12/6/202417/6/2026
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub 5.0, because `allow_all` did not take…