Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.33% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest | |
| Analizada | Media (6.1) | 0.38% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API | |
| Analizada | Alta (7.5) | 0.63% | — | Jetbrains Youtrack | 28/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | |
| Analizada | Media (6.1) | 0.45% | — | Jetbrains Youtrack | 17/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests | |
| Analizada | Media (5.4) | 0.38% | — | Jetbrains Youtrack | 10/10/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API | |
| Analizada | Media (5.3) | 0.36% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page | |
| Analizada | Media (5.3) | 0.37% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | |
| Analizada | Media (4.3) | 0.33% | — | Jetbrains Youtrack | 19/9/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project | |
| Modificada | Alta (8.1) | 0.31% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows | |
| Modificada | Alta (7.5) | 0.44% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site | |
| Modificada | Media (5.3) | 0.36% | — | Jetbrains Youtrack | 18/6/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles | |
| Analizada | Alta (7.5) | 0.27% | — | Jetbrains Youtrack | 16/5/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation | |
| Analizada | Media (6.5) | 0.52% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions | |
| Analizada | Media (6.5) | 0.52% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles | |
| Analizada | Media (5.3) | 0.48% | — | Jetbrains Youtrack | 7/3/2024 | 17/6/2026 | In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | |
| Modificada | Media (5.4) | 0.41% | — | Jetbrains Youtrack | 9/1/2024 | 17/6/2026 | In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible | |
| Modificada | Media (4.3) | 0.45% | — | Jetbrains Youtrack | 15/12/2023 | 17/6/2026 | In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed | |
| Modificada | Alta (7.3) | 0.55% | — | Jetbrains Youtrack | 12/7/2023 | 17/6/2026 | In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms | |
| Modificada | Media (5.4) | 0.97% | — | Jetbrains Youtrack | 12/6/2023 | 17/6/2026 | In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible | |
| Modificada | Alta (7.5) | 0.62% | — | Jetbrains Youtrack | 12/6/2023 | 17/6/2026 | In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms | |
| Modificada | Media (5.4) | 0.63% | — | Jetbrains Youtrack | 5/4/2022 | 17/6/2026 | In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI | |
| Modificada | Media (5.4) | 0.40% | — | Jetbrains Youtrack | 5/4/2022 | 17/6/2026 | In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description | |
| Modificada | Media (5.4) | 1.4% | — | Jetbrains Youtrack | 5/4/2022 | 17/6/2026 | In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered | |
| Modificada | Crítica (9.8) | 3.8% | 💥 PoC | Jetbrains Youtrack | 25/2/2022 | 17/6/2026 | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. |