Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.22% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies | |
| Analizada | Crítica (9.4) | 0.29% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows | |
| Analizada | Crítica (9.8) | 0.18% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions | |
| Analizada | Alta (7.5) | 0.13% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration | |
| Analizada | Alta (8.8) | 0.16% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow | |
| Analizada | Media (4.8) | 1.2% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible | |
| Analizada | Media (4.3) | 0.36% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions | |
| Analizada | Media (4.8) | 37% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible | |
| Analizada | Media (5.4) | 38% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible | |
| Analizada | Media (5.4) | 0.97% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible | |
| Analizada | Media (6.1) | 0.26% | — | Jetbrains Teamcity | 20/5/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page | |
| Analizada | Media (5.4) | 0.73% | — | Jetbrains Teamcity | 20/5/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible | |
| Analizada | Media (5.4) | 0.73% | — | Jetbrains Teamcity | 20/5/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible | |
| Analizada | Media (5.4) | 2.7% | — | Jetbrains Teamcity | 20/5/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible | |
| Analizada | Media (6.1) | 63% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab | |
| Analizada | Crítica (9.8) | 0.55% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible | |
| Analizada | Media (6.5) | 1.0% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs | |
| Analizada | Alta (7.5) | 0.36% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page | |
| Analizada | Media (6.1) | 28% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page | |
| Analizada | Media (6.5) | 1.0% | — | Jetbrains Teamcity | 27/3/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log | |
| Analizada | Media (6.1) | 0.38% | — | Jetbrains Teamcity | 11/2/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab | |
| Analizada | Crítica (9.1) | 0.42% | — | Jetbrains Teamcity | 11/2/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources | |
| Analizada | Media (6.5) | 0.31% | — | Jetbrains Teamcity | 21/1/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint | |
| Analizada | Media (4.3) | 0.27% | — | Jetbrains Teamcity | 21/1/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool | |
| Analizada | Media (6.1) | 2.8% | — | Jetbrains Teamcity | 21/1/2025 | 17/6/2026 | In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page |