Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.80% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page | |
| Analizada | Alta (8.8) | 0.31% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles | |
| Analizada | Media (4.3) | 0.29% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects | |
| Analizada | Media (5.3) | 0.29% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs | |
| Analizada | Media (4.3) | 0.29% | 💥 PoC | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents | |
| Analizada | Media (5.3) | 0.32% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | |
| Analizada | Media (6.5) | 0.60% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | |
| Analizada | Media (5.3) | 0.42% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | |
| Analizada | Crítica (9.8) | 0.74% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | |
| Analizada | Media (6.5) | 0.36% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | |
| Analizada | Alta (7.8) | 0.11% | — | Jetbrains Webstorm | 15/11/2024 | 17/6/2026 | In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule | |
| Analizada | Media (6.1) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page | |
| Analizada | Media (5.4) | 0.33% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest | |
| Analizada | Media (6.1) | 0.38% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API | |
| Analizada | Alta (7.5) | 0.63% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | |
| Analizada | Media (5.4) | 0.22% | — | Jetbrains HUB | 28/10/2024 | 17/6/2026 | In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services | |
| Modificada | Media (5.3) | 0.35% | — | Jetbrains Ktor | 17/10/2024 | 17/6/2026 | In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure | |
| Analizada | Media (6.1) | 0.45% | — | Jetbrains Youtrack | 17/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests | |
| Analizada | Media (5.4) | 0.38% | — | Jetbrains Youtrack | 10/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API |