Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.19% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | |
| Analizada | Media (5.5) | 0.15% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | |
| Analizada | Media (6.3) | 0.15% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | |
| Analizada | Media (5.4) | 0.24% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | |
| Analizada | Media (4.4) | 0.18% | — | Jetbrains Intellij Idea | 17/8/2026 | 1/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects | |
| Analizada | Alta (8.1) | 0.35% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | |
| Analizada | Media (6.5) | 1.1% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | |
| Analizada | Alta (8.2) | 0.32% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | |
| Analizada | Media (6.5) | 1.2% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | |
| Analizada | Media (4.3) | 0.27% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | |
| Analizada | Crítica (9.1) | 0.42% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature | |
| Analizada | Alta (8.1) | 0.38% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | |
| Pendiente de análisis | Media (5.9) | 0.37% | — | Jetbrains KtorAI | 17/8/2026 | 28/8/2026 | In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 27/7/2026 | 6/8/2026 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | |
| Analizada | Alta (8.6) | 0.18% | — | Jetbrains Pycharm | 23/7/2026 | 3/8/2026 | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open | |
| En análisis | Crítica (9.1) | 0.66% | — | Jetbrains TeamcityAI | 23/7/2026 | 24/7/2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | |
| Analizada | Crítica (10) | 0.66% | — | Jetbrains Teamcity | 23/7/2026 | 11/8/2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | |
| Analizada | Crítica (9.8) | 0.48% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | |
| Analizada | Alta (8.6) | 0.39% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | |
| Analizada | Crítica (10) | 0.52% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | |
| Analizada | Crítica (10) | 0.48% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | |
| Analizada | Alta (7.8) | 0.18% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | |
| Analizada | Media (6.1) | 0.25% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Phpstorm | 23/7/2026 | 28/7/2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter |