Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.29% | — | Jetbrains Youtrack | 30/9/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters | |
| Analizada | Media (6.5) | 0.23% | — | Jetbrains HUB | 30/9/2026 | 2/10/2026 | In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | |
| Analizada | Media (6.5) | 0.10% | — | Jetbrains Rider | 30/9/2026 | 2/10/2026 | In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | |
| Analizada | Baja (2.7) | 0.23% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | |
| Analizada | Media (6.1) | 0.19% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | |
| Analizada | Alta (7.1) | 0.21% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | |
| Analizada | Media (5.4) | 0.18% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | |
| Analizada | Media (4.3) | 0.19% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | |
| Analizada | Media (4.3) | 0.65% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | |
| Analizada | Media (4.3) | 0.21% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | |
| Analizada | Alta (7.8) | 0.13% | — | Jetbrains Intellij Idea | 30/9/2026 | 2/10/2026 | In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects | |
| Analizada | Crítica (9.8) | 0.35% | — | Jetbrains Teamcity | 30/9/2026 | 2/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | |
| Analizada | Alta (8.8) | 0.46% | — | Jetbrains Teamcity | 30/9/2026 | 6/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | |
| Analizada | Alta (8.8) | 0.43% | — | Jetbrains Teamcity | 30/9/2026 | 6/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Jenkins Gradle PluginAIGradleAIJetbrains DevelocityAI | 16/9/2026 | 18/9/2026 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the… | |
| Pendiente de análisis | Media (5.9) | 0.38% | — | Jetbrains GolandAI | 7/9/2026 | 8/9/2026 | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data | |
| Pendiente de análisis | Baja (3.3) | 0.15% | — | Jetbrains Intellij IdeaAI | 7/9/2026 | 8/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Jetbrains Intellij IdeaAI | 7/9/2026 | 9/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution | |
| Pendiente de análisis | Baja (3.3) | 0.14% | — | Jetbrains Intellij IdeaAI | 7/9/2026 | 8/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | Jetbrains Intellij IdeaAI | 7/9/2026 | 9/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts | |
| Pendiente de análisis | Baja (2.8) | 0.39% | — | Jetbrains Intellij IdeaAI | 7/9/2026 | 8/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log | |
| Aplazada | Media (5.5) | 0.27% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin | |
| Aplazada | Media (4.3) | 0.27% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission | |
| Aplazada | Alta (7.7) | 0.30% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission |