Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.66% | — | Jetbrains Youtrack | 9/11/2021 | 17/6/2026 | In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jetbrains HUB | 9/11/2021 | 17/6/2026 | In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. | |
| Modificada | Media (4.3) | 0.88% | — | Jetbrains Youtrack | 6/8/2021 | 17/6/2026 | In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. | |
| Modificada | Alta (7.5) | 1.5% | — | Jetbrains Youtrack | 6/8/2021 | 17/6/2026 | In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. | |
| Modificada | Media (5.4) | 0.62% | — | Jetbrains Youtrack | 6/8/2021 | 17/6/2026 | In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. | |
| Modificada | Media (5.3) | 0.70% | — | Jetbrains Youtrack | 6/8/2021 | 17/6/2026 | In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. | |
| Modificada | Alta (7.5) | 1.1% | — | Jetbrains Youtrack | 6/8/2021 | 17/6/2026 | In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. | |
| Modificada | Crítica (9.1) | 1.3% | — | Jetbrains Youtrack | 6/8/2021 | 17/6/2026 | In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient. | |
| Modificada | Alta (7.5) | 0.62% | — | Jetbrains Teamcity | 6/8/2021 | 17/6/2026 | In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS. | |
| Modificada | Media (5.3) | 0.71% | — | Jetbrains Teamcity | 6/8/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made. | |
| Modificada | Media (5.3) | 0.54% | — | Jetbrains Teamcity | 6/8/2021 | 17/6/2026 | In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. | |
| Modificada | Alta (7.5) | 0.86% | — | Jetbrains Teamcity | 6/8/2021 | 17/6/2026 | In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jetbrains Teamcity | 6/8/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization. | |
| Modificada | Alta (8.8) | 1.4% | — | Jetbrains Rubymine | 6/8/2021 | 17/6/2026 | In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects. | |
| Modificada | Media (6.1) | 0.61% | — | Jetbrains Teamcity | 6/8/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.3, XSS was possible. | |
| Modificada | Media (6.1) | 0.55% | — | Jetbrains HUB | 6/8/2021 | 17/6/2026 | In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. | |
| Modificada | Media (6.5) | 0.66% | — | Jetbrains HUB | 6/8/2021 | 17/6/2026 | In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used. | |
| Modificada | Crítica (9.8) | 1.0% | — | Jetbrains HUB | 6/8/2021 | 17/6/2026 | In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset. | |
| Modificada | Crítica (9.8) | 3.2% | — | Jetbrains Teamcity | 11/5/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. | |
| Modificada | Crítica (9.8) | 2.3% | — | Jetbrains Teamcity | 11/5/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. | |
| Modificada | Alta (7.5) | 0.71% | — | Jetbrains Teamcity | 11/5/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange. | |
| Modificada | Alta (8.8) | 1.2% | — | Jetbrains Teamcity | 11/5/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. | |
| Modificada | Media (6.1) | 0.75% | — | Jetbrains Teamcity | 11/5/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. | |
| Modificada | Alta (7.5) | 1.3% | — | Jetbrains Teamcity | 11/5/2021 | 17/6/2026 | In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. | |
| Modificada | Alta (7.5) | 0.63% | — | Jetbrains Webstorm | 11/5/2021 | 17/6/2026 | In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. |