Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

693 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—Jetbrains Webstorm11/5/202117/6/2026
In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.
ModificadaAlta (7.5)0.94%—Jetbrains Upsource11/5/202117/6/2026
In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly
ModificadaMedia (5.4)0.46%—Jetbrains Teamcity11/5/202117/6/2026
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
ModificadaCrítica (9.8)3.2%—Jetbrains Teamcity11/5/202117/6/2026
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
ModificadaMedia (5.4)0.46%—Jetbrains Teamcity11/5/202117/6/2026
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
ModificadaMedia (5.3)0.88%—Jetbrains Teamcity11/5/202117/6/2026
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.
ModificadaBaja (2.7)0.57%—Jetbrains Teamcity11/5/202117/6/2026
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.
ModificadaAlta (7.5)1.9%—Jetbrains Youtrack11/5/202117/6/2026
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
ModificadaMedia (6.1)0.75%—Jetbrains Teamcity11/5/202117/6/2026
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
ModificadaMedia (6.1)0.78%—Jetbrains Youtrack11/5/202117/6/2026
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
ModificadaAlta (7.5)1.2%—Jetbrains Youtrack11/5/202117/6/2026
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
ModificadaAlta (7.5)0.86%—Jetbrains HUB11/5/202117/6/2026
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
ModificadaMedia (5.3)0.71%—Jetbrains Code With ME11/5/202117/6/2026
In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.
ModificadaAlta (8.8)1.3%—Jetbrains Code With ME11/5/202117/6/2026
In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.
ModificadaAlta (7.5)2.3%—Jetbrains Intellij Idea11/5/202117/6/2026
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
ModificadaAlta (7.5)1.1%—Jetbrains Intellij Idea11/5/202117/6/2026
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
ModificadaAlta (7.8)0.88%💥 PoCJetbrains Pycharm11/5/202117/6/2026
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
ModificadaAlta (7.8)0.46%—Jetbrains Intellij Idea11/5/202117/6/2026
In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.
ModificadaMedia (5.4)0.58%—Jetbrains Youtrack11/5/202117/6/2026
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
ModificadaAlta (7.5)1.5%—Jetbrains Teamcity11/5/202117/6/2026
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
ModificadaBaja (3.3)0.23%—Jetbrains Teamcity11/5/202117/6/2026
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
ModificadaMedia (5.3)0.80%—Jetbrains Phpstorm18/3/202117/6/2026
In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.
ModificadaMedia (5.3)0.76%—Jetbrains Teamcity3/2/202117/6/2026
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
ModificadaMedia (5.3)0.72%—Jetbrains Teamcity3/2/202117/6/2026
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
ModificadaAlta (7.5)1.1%—Jetbrains Teamcity3/2/202117/6/2026
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.