Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1064 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.34% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | |
| Aplazada | Media (6.5) | 0.34% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | |
| Aplazada | Baja (3.1) | 0.20% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | |
| Aplazada | Baja (3.7) | 0.26% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | |
| Aplazada | Baja (3.3) | 0.16% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | |
| Aplazada | Media (4.6) | 0.64% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | |
| Aplazada | Media (5.4) | 0.64% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible | |
| Aplazada | Media (4.3) | 0.27% | — | Jetbrains YoutrackAI | 7/9/2026 | 8/9/2026 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | |
| Aplazada | Alta (8.1) | 0.35% | — | Jetbrains YoutrackAI | 7/9/2026 | 9/9/2026 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | |
| Aplazada | Crítica (9.8) | 0.61% | — | Jetbrains YoutrackAI | 7/9/2026 | 9/9/2026 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | |
| Aplazada | Alta (8.8) | 0.42% | — | Jetbrains YoutrackAI | 7/9/2026 | 22/9/2026 | In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation | |
| Aplazada | Baja (2.1) | 0.22% | — | Toggl Track ExtensionAI | 31/8/2026 | 31/8/2026 | A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The… | |
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… | |
| Analizada | Alta (8.1) | 0.35% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | |
| Analizada | Media (6.5) | 1.1% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | |
| Analizada | Alta (8.2) | 0.32% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | |
| Analizada | Media (6.5) | 1.2% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | |
| Analizada | Media (4.3) | 0.27% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | |
| Analizada | Crítica (9.1) | 0.42% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature | |
| Analizada | Alta (8.1) | 0.38% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | |
| Pendiente de análisis | Media (5.7) | 0.11% | — | Elan Trackpoint DriverAI | 13/8/2026 | 24/8/2026 | ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash. | |
| Aplazada | Media (6.5) | 0.22% | — | Aftership TrackingAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions. | |
| Aplazada | Crítica (9.3) | 0.67% | — | React-trackedAI | 10/8/2026 | 9/9/2026 | react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd773e742627e8 that executed remote attacker-controlled code on developer machines… | |
| Aplazada | Alta (7.1) | 0.13% | — | Data443 Tracking Code ManagerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. |