Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.24% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | |
| Analizada | Media (5.4) | 0.80% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS | |
| Analizada | Media (4.9) | 0.30% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission | |
| Analizada | Media (6.5) | 0.31% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies | |
| Analizada | Media (5.4) | 0.80% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page | |
| Analizada | Alta (8.8) | 0.31% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles | |
| Analizada | Media (4.3) | 0.29% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects | |
| Analizada | Media (5.3) | 0.29% | — | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs | |
| Analizada | Media (4.3) | 0.29% | 💥 PoC | Jetbrains Teamcity | 20/12/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents | |
| Analizada | Media (5.4) | 1.4% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings | |
| Analizada | Media (5.4) | 1.4% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings | |
| Analizada | Alta (7.5) | 23% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location | |
| Analizada | Alta (7.5) | 0.53% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups | |
| Analizada | Media (6.5) | 0.31% | — | Jetbrains Teamcity | 8/10/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin | |
| Analizada | Media (6.1) | 0.33% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page | |
| Analizada | Media (5.4) | 0.24% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin | |
| Analizada | Media (5.4) | 0.31% | — | Jetbrains Teamcity | 16/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page | |
| Analizada | Alta (7.8) | 0.15% | — | Jetbrains Teamcity | 6/8/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions | |
| Modificada | Alta (7.5) | 0.33% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection | |
| Modificada | Media (6.5) | 0.28% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time | |
| Modificada | Crítica (9.8) | 0.40% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration | |
| Modificada | Media (4.8) | 0.30% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page | |
| Modificada | Media (5.4) | 0.27% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab | |
| Modificada | Media (6.5) | 0.30% | — | Jetbrains Teamcity | 22/7/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases |