Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Phpstorm | 23/7/2026 | 28/7/2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling | |
| Analizada | Alta (7.8) | 0.18% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling | |
| Analizada | Alta (7.8) | 0.21% | — | Jetbrains Goland | 23/7/2026 | 28/7/2026 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK | |
| Analizada | Alta (7.8) | 0.21% | — | Jetbrains Goland | 23/7/2026 | 28/7/2026 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration | |
| Analizada | Media (5.7) | 0.85% | — | Jetbrains Goland | 23/7/2026 | 28/7/2026 | In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default | |
| Analizada | Crítica (9.8) | 0.61% | — | Jetbrains Youtrack | 14/7/2026 | 12/8/2026 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | |
| Aplazada | Alta (7.5) | 0.51% | — | Jetbrains AquaAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2. | |
| Analizada | Media (6.1) | 0.66% | — | Jetbrains Youtrack | 10/7/2026 | 10/7/2026 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible | |
| Analizada | Alta (8.1) | 0.35% | — | Jetbrains Teamcity | 10/7/2026 | 14/7/2026 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | |
| Analizada | Media (6.1) | 0.34% | — | Jetbrains Teamcity | 10/7/2026 | 13/7/2026 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Teamcity | 10/7/2026 | 10/7/2026 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | |
| Analizada | Alta (8.8) | 0.49% | — | Jetbrains Teamcity | 10/7/2026 | 14/7/2026 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | |
| Analizada | Crítica (9.8) | 0.60% | — | Jetbrains Intellij Idea | 10/7/2026 | 14/7/2026 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible | |
| Analizada | Baja (3.5) | 0.23% | — | Jetbrains Youtrack | 10/7/2026 | 10/7/2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | |
| Analizada | Crítica (9.8) | 0.34% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details | |
| Analizada | Alta (7.5) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings | |
| Analizada | Media (5.3) | 0.24% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible | |
| Analizada | Alta (7.5) | 0.30% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint | |
| Analizada | Crítica (9.8) | 0.33% | — | Jetbrains Kotlin | 26/6/2026 | 27/6/2026 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata | |
| Analizada | Alta (8.8) | 0.62% | — | Jetbrains HUB | 19/6/2026 | 26/6/2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible |