Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.48% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector | |
| Modificada | Media (5.4) | 75% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings | |
| Modificada | Media (6.1) | 0.38% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration | |
| Analizada | Alta (7.4) | 0.54% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter | |
| Modificada | Media (6.1) | 0.48% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 open redirect was possible on the login page | |
| Analizada | Media (6.5) | 0.43% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled | |
| Analizada | Alta (7.8) | 0.23% | — | Jetbrains Teamcity | 21/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process | |
| Analizada | Media (6.5) | 0.52% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions | |
| Analizada | Media (6.5) | 0.52% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles | |
| Analizada | Media (5.3) | 0.48% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | |
| Analizada | Media (5.8) | 0.34% | — | Jetbrains Teamcity | 6/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly | |
| Analizada | Media (4.3) | 0.53% | — | Jetbrains Teamcity | 6/3/2024 | 17/6/2026 | In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed | |
| Analizada | Alta (7.3) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 4/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 4/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | |
| Modificada | Media (5.5) | 0.41% | — | Jetbrains Toolbox | 6/2/2024 | 17/6/2026 | In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image | |
| Modificada | Media (5.3) | 32% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | |
| Modificada | Media (5.3) | 0.32% | — | Jetbrains Intellij Idea | 6/2/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL | |
| Modificada | Media (4.3) | 0.27% | — | Jetbrains Intellij Idea | 6/2/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives | |
| Modificada | Media (5.3) | 0.28% | — | Jetbrains Rider | 6/2/2024 | 17/6/2026 | In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible | |
| Modificada | Media (5.3) | 0.74% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation | |
| Modificada | Media (5.4) | 0.36% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible | |
| Modificada | Media (5.3) | 0.31% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible | |
| Modificada | Media (5.4) | 0.41% | — | Jetbrains Youtrack | 9/1/2024 | 17/6/2026 | In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible | |
| Modificada | Crítica (9.8) | 0.33% | — | Jetbrains Intellij Idea | 21/12/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration |