Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

693 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.38%—Jetbrains Teamcity23/2/202317/6/2026
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
ModificadaMedia (6.1)59%—Jetbrains Teamcity23/2/202317/6/2026
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
ModificadaCrítica (9.8)0.31%—Jetbrains Teamcity23/2/202317/6/2026
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
ModificadaAlta (7.8)0.26%—Jetbrains Intellij Idea22/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
ModificadaAlta (7.5)0.22%—Jetbrains Intellij Idea22/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
ModificadaMedia (4.9)0.46%—Jetbrains Teamcity8/12/202217/6/2026
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
ModificadaMedia (5.3)0.48%—Jetbrains Teamcity8/12/202217/6/2026
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
ModificadaAlta (8.8)0.44%—Jetbrains Gateway8/12/202217/6/2026
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
ModificadaAlta (7.8)0.28%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
ModificadaMedia (5.5)0.20%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
ModificadaMedia (5.5)0.23%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
ModificadaBaja (3.3)0.13%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
ModificadaAlta (7.8)0.18%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
ModificadaAlta (7.5)0.55%—Jetbrains HUB18/11/202217/6/2026
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
ModificadaMedia (5.3)0.38%—Jetbrains Teamcity3/11/202217/6/2026
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
ModificadaAlta (7.5)0.57%—Jetbrains Teamcity3/11/202217/6/2026
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
ModificadaAlta (7.5)0.57%—Jetbrains Teamcity3/11/202217/6/2026
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
ModificadaMedia (5.3)0.47%—Jetbrains Teamcity3/11/202217/6/2026
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
ModificadaMedia (5.3)0.36%—Jetbrains Teamcity23/9/202217/6/2026
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
ModificadaAlta (7.8)0.26%—Jetbrains Intellij Idea19/9/202217/6/2026
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
ModificadaMedia (6.5)0.73%—Jetbrains Ktor12/8/202217/6/2026
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
ModificadaMedia (6.1)0.48%—Jetbrains Ktor12/8/202217/6/2026
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
ModificadaMedia (5.3)0.44%—Jetbrains Teamcity10/8/202217/6/2026
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
ModificadaAlta (7.8)0.20%—Jetbrains Rider3/8/202217/6/2026
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
ModificadaBaja (3.3)0.18%—Jetbrains Intellij Idea28/7/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed