Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.25% | — | Jetbrains Intellij Idea | 28/7/2022 | 2/10/2026 | In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible | |
| Modificada | Alta (8.8) | 0.67% | — | Jetbrains Teamcity | 20/7/2022 | 17/6/2026 | In JetBrains TeamCity before 2022.04.2 build parameter injection was possible | |
| Modificada | Media (6.5) | 1.9% | — | Jetbrains Teamcity | 20/7/2022 | 17/6/2026 | In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases | |
| Modificada | Media (5.3) | 0.59% | — | Jetbrains HUB | 1/7/2022 | 17/6/2026 | In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services | |
| Modificada | Media (4.9) | 0.89% | — | Jetbrains Ktor | 12/5/2022 | 17/6/2026 | SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1. | |
| Modificada | Media (6.1) | 0.47% | — | Jetbrains Teamcity | 12/5/2022 | 17/6/2026 | In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible | |
| Modificada | Media (4.9) | 0.49% | — | Jetbrains Teamcity | 12/5/2022 | 17/6/2026 | In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible | |
| Modificada | Media (6.1) | 1.5% | — | Jetbrains Teamcity | 12/5/2022 | 17/6/2026 | In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible | |
| Modificada | Alta (7.7) | 0.23% | — | Jetbrains Pycharm | 28/4/2022 | 17/6/2026 | In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible | |
| Modificada | Baja (3.5) | 0.39% | — | Jetbrains Pycharm | 28/4/2022 | 17/6/2026 | In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible | |
| Modificada | Alta (7.7) | 0.23% | — | Jetbrains Intellij Idea | 28/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible | |
| Modificada | Alta (7.1) | 0.15% | — | Jetbrains Intellij Idea | 28/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed | |
| Modificada | Media (6.1) | 0.39% | — | Jetbrains Intellij Idea | 28/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible | |
| Modificada | Baja (3.2) | 0.27% | — | Jetbrains Intellij Idea | 28/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible | |
| Modificada | Media (6.7) | 0.22% | — | Jetbrains Intellij Idea | 28/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible | |
| Modificada | Alta (7.7) | 0.23% | — | Jetbrains Intellij Idea | 28/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible | |
| Modificada | Media (6.7) | 0.22% | — | Jetbrains Intellij Idea | 28/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible | |
| Modificada | Baja (2.3) | 0.18% | — | Jetbrains Intellij Idea | 28/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient | |
| Modificada | Media (4.8) | 0.48% | — | Jetbrains HUB | 28/4/2022 | 17/6/2026 | In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible. | |
| Modificada | Baja (2.7) | 0.62% | — | Jetbrains Ktor | 11/4/2022 | 17/6/2026 | In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations | |
| Modificada | Media (5.5) | 0.32% | — | Jetbrains Intellij Idea | 5/4/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields | |
| Modificada | Media (5.4) | 0.63% | — | Jetbrains Youtrack | 5/4/2022 | 17/6/2026 | In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI | |
| Modificada | Media (5.4) | 0.40% | — | Jetbrains Youtrack | 5/4/2022 | 17/6/2026 | In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description | |
| Modificada | Media (5.4) | 1.4% | — | Jetbrains Youtrack | 5/4/2022 | 17/6/2026 | In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered | |
| Modificada | Alta (7.5) | 0.96% | — | Jetbrains Teamcity | 25/2/2022 | 17/6/2026 | In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases. |