Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.44% | — | Microsoft Authenticator | 8/9/2026 | 24/9/2026 | Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Baja (1.9) | 0.15% | — | Extension.vn 2FA Authenticator ExtensionAI | 31/8/2026 | 2/9/2026 | A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service Worker. Executing a manipulation of the argument sender.id can lead to information disclosure. The attack… | |
| Aplazada | Media (6.5) | 0.18% | — | Miniorange Google AuthenticatorAI | 6/8/2026 | 26/8/2026 | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account. | |
| Analizada | Alta (7.5) | 0.53% | — | Fortinet Fortiauthenticator | 14/7/2026 | 29/9/2026 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. | |
| Analizada | Alta (7.4) | 1.1% | — | Microsoft Authenticator | 14/5/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.8) | 0.48% | — | Fortinet Fortiauthenticator | 12/5/2026 | 17/6/2026 | A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests. | |
| Analizada | Media (5.9) | 0.41% | — | LTI Jupyterhub Authenticator | 3/4/2026 | 24/7/2026 | LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests… | |
| Analizada | Alta (8.8) | 0.64% | — | Jupyter Oauthenticator | 3/4/2026 | 24/7/2026 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the… | |
| Modificada | Crítica (9.3) | 0.47% | — | Gematik Authenticator | 27/3/2026 | 17/6/2026 | Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to… | |
| Modificada | Alta (7.8) | 0.30% | — | Gematik Authenticator | 27/3/2026 | 17/6/2026 | Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authenticator to version… | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft Authenticator | 10/3/2026 | 17/6/2026 | Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.2) | 0.36% | — | Fortinet Fortiauthenticator | 10/2/2026 | 17/6/2026 | A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected endpoint. | |
| Modificada | Baja (2.7) | 0.21% | — | Fortinet Fortiauthenticator | 9/12/2025 | 17/6/2026 | An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other… | |
| Analizada | Baja (2.7) | 0.23% | — | Fortinet Fortiauthenticator | 9/12/2025 | 30/9/2026 | A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via… | |
| Aplazada | Alta (7.2) | 0.15% | — | Netknights Gmbh Privacyidea AuthenticatorAI | 27/10/2025 | 17/6/2026 | Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of… | |
| Analizada | Alta (8.8) | 0.35% | — | Authenticator Login Project Authenticator Login | 10/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8. | |
| Analizada | Media (6.9) | 0.22% | — | Qnap Authenticator | 3/10/2025 | 17/6/2026 | An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP Authenticator 1.3.1.1227 and later | |
| Analizada | Crítica (9.8) | 0.52% | — | Authenticator Login Project Authenticator Login | 15/8/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4. | |
| Analizada | Crítica (9.8) | 0.42% | — | Authenticator Login Project Authenticator Login | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6. | |
| Analizada | Crítica (9.8) | 0.36% | — | LTI Jupyterhub Authenticator | 25/2/2025 | 17/6/2026 | `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has… | |
| Aplazada | Media (4) | 0.14% | — | Nitrokey 3 FirmwareAIPIV AuthenticatorAI | 12/2/2025 | 17/6/2026 | Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for authentication of the admin key. This could lead to compromise of the integrity of the data stored in the application. An attacker… | |
| Modificada | Media (6.1) | 0.45% | — | Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+10 | 22/1/2025 | 17/6/2026 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | |
| Modificada | Alta (7.8) | 0.09% | — | Authenticator | 3/9/2024 | 17/6/2026 | Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key.… | |
| Analizada | Media (5.3) | 1.7% | ⚠ Explotación activa | Twilio AuthyTwilio Authy Authenticator | 2/7/2024 | 17/6/2026 | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with… | |
| Aplazada | Alta (8.1) | 0.40% | — | JupyterhubAIJupyter OauthenticatorAI | 12/6/2024 | 17/6/2026 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub 5.0, because `allow_all` did not take… |