Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

84 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.11%—Jetbrains Intellij Idea16/12/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
AnalizadaMedia (4.6)0.43%—Jetbrains Intellij Idea20/8/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
AnalizadaAlta (7.3)0.13%—Jetbrains Intellij Idea20/8/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
AnalizadaMedia (6.5)0.25%—Jetbrains Intellij Idea20/8/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
AnalizadaAlta (7.5)0.20%—Jetbrains Intellij Idea20/8/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
AplazadaAlta (8.8)0.36%—Anthropic Claude CodeAIMicrosoft VscodeAIJetbrains IntellijAIJetbrains PycharmAI+124/6/202517/6/2026
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for…
AnalizadaBaja (3.3)0.43%—Jetbrains Intellij Idea3/4/202517/6/2026
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
AnalizadaMedia (6.1)0.39%—Jetbrains Intellij Idea16/9/202417/6/2026
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
AnalizadaBaja (1)0.11%—Google Bazel FOR Android StudioGoogle Bazel FOR ClionGoogle Bazel FOR Intellij18/6/202417/6/2026
When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls ProjectManager.getInstance().createProject. This method, as its name…
ModificadaAlta (7.5)3.8%💥 PoCJetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+910/6/202417/6/2026
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell…
ModificadaMedia (5.3)0.32%—Jetbrains Intellij Idea6/2/202417/6/2026
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
ModificadaMedia (4.3)0.27%—Jetbrains Intellij Idea6/2/202417/6/2026
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
ModificadaCrítica (9.8)0.33%—Jetbrains Intellij Idea21/12/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
ModificadaAlta (7.8)0.28%—Jetbrains Intellij Idea26/7/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
ModificadaBaja (3.3)0.17%—Jetbrains Intellij Idea12/7/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
ModificadaAlta (7.5)0.65%—Jetbrains Intellij Idea29/3/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
ModificadaAlta (8.8)0.15%—Jetbrains Intellij Idea29/3/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
ModificadaAlta (7.8)0.10%—Jetbrains Intellij Idea29/3/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
ModificadaAlta (7.5)0.33%—Jetbrains Intellij Idea29/3/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
ModificadaAlta (7.8)0.26%—Jetbrains Intellij Idea22/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
ModificadaAlta (7.5)0.22%—Jetbrains Intellij Idea22/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
ModificadaAlta (7.8)0.28%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
ModificadaMedia (5.5)0.20%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
ModificadaMedia (5.5)0.23%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
ModificadaBaja (3.3)0.13%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
Orbitaley — Vulnerabilidades