Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

82 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.11%—Jetbrains Intellij Idea16/12/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
AnalizadaMedia (4.6)0.43%—Jetbrains Intellij Idea20/8/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
AnalizadaAlta (7.3)0.13%—Jetbrains Intellij Idea20/8/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
AnalizadaMedia (6.5)0.25%—Jetbrains Intellij Idea20/8/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
AnalizadaAlta (7.5)0.20%—Jetbrains Intellij Idea20/8/202517/6/2026
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
AnalizadaBaja (3.3)0.43%—Jetbrains Intellij Idea3/4/202517/6/2026
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
AnalizadaMedia (6.1)0.39%—Jetbrains Intellij Idea16/9/202417/6/2026
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
ModificadaAlta (7.5)3.8%💥 PoCJetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+910/6/202417/6/2026
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell…
ModificadaMedia (5.3)0.32%—Jetbrains Intellij Idea6/2/202417/6/2026
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
ModificadaMedia (4.3)0.27%—Jetbrains Intellij Idea6/2/202417/6/2026
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
ModificadaCrítica (9.8)0.33%—Jetbrains Intellij Idea21/12/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
ModificadaAlta (7.8)0.28%—Jetbrains Intellij Idea26/7/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
ModificadaBaja (3.3)0.17%—Jetbrains Intellij Idea12/7/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
ModificadaAlta (7.5)0.65%—Jetbrains Intellij Idea29/3/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
ModificadaAlta (8.8)0.15%—Jetbrains Intellij Idea29/3/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
ModificadaAlta (7.8)0.10%—Jetbrains Intellij Idea29/3/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
ModificadaAlta (7.5)0.33%—Jetbrains Intellij Idea29/3/202317/6/2026
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
ModificadaAlta (7.8)0.26%—Jetbrains Intellij Idea22/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
ModificadaAlta (7.5)0.22%—Jetbrains Intellij Idea22/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
ModificadaAlta (7.8)0.28%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
ModificadaMedia (5.5)0.20%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
ModificadaMedia (5.5)0.23%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
ModificadaBaja (3.3)0.13%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
ModificadaAlta (7.8)0.18%—Jetbrains Intellij Idea8/12/202217/6/2026
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
ModificadaAlta (7.8)0.26%—Jetbrains Intellij Idea19/9/202217/6/2026
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
Orbitaley — Vulnerabilidades