Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
84 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.11% | — | Jetbrains Intellij Idea | 16/12/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH | |
| Analizada | Media (4.6) | 0.43% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature | |
| Analizada | Alta (7.3) | 0.13% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start | |
| Analizada | Media (6.5) | 0.25% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files | |
| Analizada | Alta (7.5) | 0.20% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference | |
| Aplazada | Alta (8.8) | 0.36% | — | Anthropic Claude CodeAIMicrosoft VscodeAIJetbrains IntellijAIJetbrains PycharmAI+1 | 24/6/2025 | 17/6/2026 | Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for… | |
| Analizada | Baja (3.3) | 0.43% | — | Jetbrains Intellij Idea | 3/4/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file | |
| Analizada | Media (6.1) | 0.39% | — | Jetbrains Intellij Idea | 16/9/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible | |
| Analizada | Baja (1) | 0.11% | — | Google Bazel FOR Android StudioGoogle Bazel FOR ClionGoogle Bazel FOR Intellij | 18/6/2024 | 17/6/2026 | When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls ProjectManager.getInstance().createProject. This method, as its name… | |
| Modificada | Alta (7.5) | 3.8% | 💥 PoC | Jetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+9 | 10/6/2024 | 17/6/2026 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell… | |
| Modificada | Media (5.3) | 0.32% | — | Jetbrains Intellij Idea | 6/2/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL | |
| Modificada | Media (4.3) | 0.27% | — | Jetbrains Intellij Idea | 6/2/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives | |
| Modificada | Crítica (9.8) | 0.33% | — | Jetbrains Intellij Idea | 21/12/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration | |
| Modificada | Alta (7.8) | 0.28% | — | Jetbrains Intellij Idea | 26/7/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions | |
| Modificada | Baja (3.3) | 0.17% | — | Jetbrains Intellij Idea | 12/7/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases | |
| Modificada | Alta (7.5) | 0.65% | — | Jetbrains Intellij Idea | 29/3/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server. | |
| Modificada | Alta (8.8) | 0.15% | — | Jetbrains Intellij Idea | 29/3/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed. | |
| Modificada | Alta (7.8) | 0.10% | — | Jetbrains Intellij Idea | 29/3/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation. | |
| Modificada | Alta (7.5) | 0.33% | — | Jetbrains Intellij Idea | 29/3/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview. | |
| Modificada | Alta (7.8) | 0.26% | — | Jetbrains Intellij Idea | 22/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. | |
| Modificada | Alta (7.5) | 0.22% | — | Jetbrains Intellij Idea | 22/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files. | |
| Modificada | Alta (7.8) | 0.28% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. | |
| Modificada | Media (5.5) | 0.20% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible. | |
| Modificada | Media (5.5) | 0.23% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability. | |
| Modificada | Baja (3.3) | 0.13% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects. |