Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2782▼ 316 respecto a la semana anterior
Críticas / altas1289▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

14.266 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.56%💥 PoCBrainstormforce SureformsAI18/8/20263/9/2026
CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is…
AplazadaAlta (7.5)0.58%💥 PoCBrainstormforce SureformsAI18/8/20263/9/2026
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface,…
AplazadaMedia (6.9)0.74%—Maalfer MailerupAI18/8/20261/9/2026
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription…
AplazadaCrítica (9.8)0.56%—Kainelabs YouzifyAI18/8/202620/8/2026
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
AplazadaAlta (7.1)0.25%—Kaizencoders URL ShortifyAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
AplazadaAlta (7.1)0.25%—Brainstormforce Convert PROAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
AplazadaMedia (5.5)0.43%—Phpgurukul Complaint Management SystemAI18/8/202620/8/2026
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the argument email causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to…
AplazadaCrítica (9.8)0.86%—Rainygao DocsysAI17/8/202631/8/2026
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
AplazadaCrítica (9.8)0.60%—Brainformatik Crm+AI17/8/20269/9/2026
The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL…
AnalizadaAlta (8.4)0.18%—Jetbrains Pycharm17/8/202610/9/2026
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
AnalizadaMedia (4.4)0.18%—Jetbrains Pycharm17/8/202610/9/2026
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
AnalizadaMedia (5.5)0.15%—Jetbrains Intellij Idea17/8/202611/9/2026
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
AnalizadaMedia (6.2)0.17%—Jetbrains Intellij Idea17/8/202611/9/2026
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
AnalizadaAlta (7.8)0.19%—Jetbrains Intellij Idea17/8/202611/9/2026
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
AnalizadaMedia (5.5)0.15%—Jetbrains Intellij Idea17/8/202611/9/2026
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
AnalizadaMedia (6.3)0.15%—Jetbrains Intellij Idea17/8/202611/9/2026
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
AnalizadaMedia (5.4)0.24%—Jetbrains Intellij Idea17/8/202611/9/2026
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
AnalizadaMedia (4.4)0.18%—Jetbrains Intellij Idea17/8/20261/9/2026
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
AnalizadaAlta (8.1)0.35%—Jetbrains Youtrack17/8/202615/9/2026
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
AnalizadaMedia (6.5)1.1%—Jetbrains Youtrack17/8/202615/9/2026
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
AnalizadaMedia (6.5)0.34%—Jetbrains Youtrack17/8/202615/9/2026
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
AnalizadaAlta (8.2)0.32%—Jetbrains Youtrack17/8/202615/9/2026
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
AnalizadaMedia (6.5)1.2%—Jetbrains Youtrack17/8/202615/9/2026
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
AnalizadaMedia (4.3)0.27%—Jetbrains Youtrack17/8/202615/9/2026
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
AnalizadaCrítica (9.1)0.42%—Jetbrains Youtrack17/8/202615/9/2026
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature