Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.25% | — | Jetbrains Rubymine | 17/4/2025 | 17/6/2026 | In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces | |
| Analizada | Media (6.5) | 0.23% | — | Jetbrains Toolbox | 17/4/2025 | 17/6/2026 | In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation | |
| Analizada | Alta (7.5) | 0.15% | — | Jetbrains Toolbox | 17/4/2025 | 17/6/2026 | In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible | |
| Analizada | Crítica (9.8) | 0.63% | — | Jetbrains Toolbox | 17/4/2025 | 17/6/2026 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible | |
| Analizada | Media (6.5) | 0.20% | — | Jetbrains Toolbox | 17/4/2025 | 17/6/2026 | In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin | |
| Analizada | Baja (3.3) | 0.43% | — | Jetbrains Intellij Idea | 3/4/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file | |
| Analizada | Alta (7.5) | 0.36% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page | |
| Analizada | Media (6.1) | 28% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page | |
| Analizada | Media (6.5) | 1.0% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log | |
| Analizada | Media (5.3) | 0.18% | — | Jetbrains Goland | 25/3/2025 | 17/6/2026 | In JetBrains GoLand before 2025.1 an XXE during debugging was possible | |
| Analizada | Media (5.3) | 0.33% | — | Jetbrains Ktor | 12/3/2025 | 17/6/2026 | In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible | |
| Analizada | Alta (7.8) | 0.19% | — | Jetbrains Runtime | 12/3/2025 | 17/6/2026 | In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible | |
| Analizada | Media (6.1) | 0.38% | — | Jetbrains Teamcity | 11/2/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab | |
| Analizada | Crítica (9.1) | 0.42% | — | Jetbrains Teamcity | 11/2/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources | |
| Analizada | Alta (7.8) | 0.14% | — | Jetbrains DottraceJetbrains ETW Host ServiceJetbrains ResharperJetbrains Rider | 28/1/2025 | 17/6/2026 | In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible | |
| Analizada | Media (6.5) | 0.31% | — | Jetbrains Teamcity | 21/1/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint | |
| Analizada | Media (4.3) | 0.27% | — | Jetbrains Teamcity | 21/1/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool | |
| Analizada | Media (6.1) | 2.8% | — | Jetbrains Teamcity | 21/1/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page | |
| Analizada | Alta (7.8) | 0.22% | — | Jetbrains Youtrack | 21/1/2025 | 17/6/2026 | In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | |
| Analizada | Media (5.5) | 0.60% | — | Jetbrains Youtrack | 21/1/2025 | 17/6/2026 | In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | |
| Analizada | Alta (8.8) | 0.29% | — | Jetbrains HUB | 21/1/2025 | 17/6/2026 | In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping | |
| Analizada | Alta (7.1) | 0.24% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | |
| Analizada | Media (5.4) | 0.80% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS | |
| Analizada | Media (4.9) | 0.30% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission | |
| Analizada | Media (6.5) | 0.31% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies |