Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.11% | — | Jetbrains Intellij Idea | 16/12/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH | |
| Analizada | Media (4.6) | 0.43% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature | |
| Analizada | Alta (7.3) | 0.13% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start | |
| Analizada | Media (6.5) | 0.25% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files | |
| Analizada | Alta (7.5) | 0.20% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference | |
| Analizada | Baja (3.3) | 0.43% | — | Jetbrains Intellij Idea | 3/4/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file | |
| Analizada | Media (6.1) | 0.39% | — | Jetbrains Intellij Idea | 16/9/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible | |
| Modificada | Alta (7.5) | 3.8% | 💥 PoC | Jetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+9 | 10/6/2024 | 17/6/2026 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell… | |
| Modificada | Media (5.3) | 0.32% | — | Jetbrains Intellij Idea | 6/2/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL | |
| Modificada | Media (4.3) | 0.27% | — | Jetbrains Intellij Idea | 6/2/2024 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives | |
| Modificada | Crítica (9.8) | 0.33% | — | Jetbrains Intellij Idea | 21/12/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration | |
| Modificada | Alta (7.8) | 0.28% | — | Jetbrains Intellij Idea | 26/7/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions | |
| Modificada | Baja (3.3) | 0.17% | — | Jetbrains Intellij Idea | 12/7/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases | |
| Modificada | Alta (7.5) | 0.65% | — | Jetbrains Intellij Idea | 29/3/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server. | |
| Modificada | Alta (8.8) | 0.15% | — | Jetbrains Intellij Idea | 29/3/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed. | |
| Modificada | Alta (7.8) | 0.10% | — | Jetbrains Intellij Idea | 29/3/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation. | |
| Modificada | Alta (7.5) | 0.33% | — | Jetbrains Intellij Idea | 29/3/2023 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview. | |
| Modificada | Alta (7.8) | 0.26% | — | Jetbrains Intellij Idea | 22/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. | |
| Modificada | Alta (7.5) | 0.22% | — | Jetbrains Intellij Idea | 22/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files. | |
| Modificada | Alta (7.8) | 0.28% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. | |
| Modificada | Media (5.5) | 0.20% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible. | |
| Modificada | Media (5.5) | 0.23% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability. | |
| Modificada | Baja (3.3) | 0.13% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects. | |
| Modificada | Alta (7.8) | 0.18% | — | Jetbrains Intellij Idea | 8/12/2022 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible. | |
| Modificada | Alta (7.8) | 0.26% | — | Jetbrains Intellij Idea | 19/9/2022 | 17/6/2026 | The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking |