Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | |
| Analizada | Alta (7.2) | 0.54% | — | Jetbrains Youtrack | 17/4/2026 | 17/6/2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass | |
| Analizada | Media (5.3) | 0.35% | — | Jetbrains Youtrack | 25/2/2026 | 17/6/2026 | In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint | |
| Analizada | Media (6.5) | 1.1% | — | Jetbrains Youtrack | 9/2/2026 | 17/6/2026 | In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs | |
| Modificada | Baja (3.7) | 0.21% | — | Jetbrains Youtrack | 11/11/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit | |
| Analizada | Alta (7.5) | 0.22% | — | Jetbrains Youtrack | 10/11/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure | |
| Analizada | Alta (7.5) | 0.31% | — | Jetbrains Youtrack | 10/11/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form | |
| Analizada | Media (5.4) | 0.28% | — | Jetbrains Youtrack | 20/8/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content | |
| Analizada | Media (6.1) | 0.26% | — | Jetbrains Youtrack | 28/7/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions | |
| Analizada | Alta (7.6) | 0.29% | — | Jetbrains Youtrack | 15/7/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible | |
| Analizada | Alta (7.5) | 0.41% | — | Jetbrains Youtrack | 20/5/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API | |
| Analizada | Media (5.3) | 0.37% | — | Jetbrains Youtrack | 20/5/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning | |
| Analizada | Alta (7.8) | 0.22% | — | Jetbrains Youtrack | 21/1/2025 | 17/6/2026 | In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | |
| Analizada | Media (5.5) | 0.60% | — | Jetbrains Youtrack | 21/1/2025 | 17/6/2026 | In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | |
| Analizada | Media (5.3) | 0.32% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | |
| Analizada | Media (6.5) | 0.60% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | |
| Analizada | Media (5.3) | 0.42% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | |
| Analizada | Crítica (9.8) | 0.74% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | |
| Analizada | Media (6.5) | 0.36% | — | Jetbrains Youtrack | 4/12/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule | |
| Analizada | Media (6.1) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page |