Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 1.4% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings | |
| Analizada | Media (5.4) | 1.4% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings | |
| Analizada | Alta (7.5) | 23% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location | |
| Analizada | Alta (7.5) | 0.53% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups | |
| Analizada | Media (6.5) | 0.31% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API | |
| Analizada | Media (5.3) | 0.36% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page | |
| Analizada | Media (5.3) | 0.37% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | |
| Analizada | Media (4.3) | 0.33% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project | |
| Analizada | Media (6.1) | 0.39% | — | Jetbrains Intellij Idea | 16/9/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin | |
| Analizada | Media (6.1) | 0.33% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page | |
| Analizada | Media (5.4) | 0.24% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin | |
| Analizada | Media (5.4) | 0.31% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page | |
| Analizada | Alta (7.8) | 0.15% | — | Jetbrains Teamcity | 6/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions | |
| Modificada | Alta (7.5) | 0.33% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection | |
| Modificada | Media (6.5) | 0.28% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time | |
| Modificada | Crítica (9.8) | 0.40% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration | |
| Modificada | Media (4.8) | 0.30% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page | |
| Modificada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab | |
| Modificada | Media (6.5) | 0.30% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases | |
| Modificada | Media (5.3) | 0.29% | — | Jetbrains Teamcity | 1/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings | |
| Modificada | Media (5.3) | 0.28% | — | Jetbrains Teamcity | 1/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection | |
| Modificada | Media (5.4) | 0.24% | — | Jetbrains HUB | 18/6/2024 | 17/6/2026 | In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible | |
| Modificada | Alta (8.1) | 0.31% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows | |
| Modificada | Alta (7.5) | 0.44% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site |