Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 5 respecto a la semana anterior
Críticas / altas1274▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
14.294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 0.66% | — | Jetbrains Teamcity | 23/7/2026 | 11/8/2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | |
| Analizada | Crítica (9.8) | 0.48% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | |
| Analizada | Alta (8.6) | 0.39% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | |
| Analizada | Crítica (10) | 0.52% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | |
| Analizada | Crítica (10) | 0.48% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | |
| Analizada | Alta (7.8) | 0.18% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | |
| Analizada | Media (6.1) | 0.25% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Phpstorm | 23/7/2026 | 28/7/2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Phpstorm | 23/7/2026 | 28/7/2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling | |
| Analizada | Alta (7.8) | 0.18% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling | |
| Analizada | Alta (7.8) | 0.21% | — | Jetbrains Goland | 23/7/2026 | 28/7/2026 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK | |
| Analizada | Alta (7.8) | 0.21% | — | Jetbrains Goland | 23/7/2026 | 28/7/2026 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration | |
| Analizada | Media (5.7) | 0.85% | — | Jetbrains Goland | 23/7/2026 | 28/7/2026 | In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default | |
| Aplazada | Alta (7.1) | 0.13% | — | MailpoetAI | 23/7/2026 | 23/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | |
| Aplazada | Crítica (9.1) | 0.50% | — | MailsterAI | 23/7/2026 | 23/7/2026 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | |
| Aplazada | Crítica (9.8) | 0.71% | 💥 PoC | Mountdev AI MCP ConnectorAI | 23/7/2026 | 23/7/2026 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an… | |
| Aplazada | Media (6.5) | 0.45% | — | AI Copilot Content GeneratorAI | 23/7/2026 | 23/7/2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Redhat Openshift AIAIRedhat ODH DashboardAI | 23/7/2026 | 30/9/2026 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the… | |
| Aplazada | Alta (7.5) | 0.41% | — | Praison AI SEOAI | 23/7/2026 | 23/7/2026 | The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data. | |
| Aplazada | Media (6.3) | 0.44% | — | InvokeaiAI | 22/7/2026 | 23/7/2026 | InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to… | |
| Pendiente de análisis | Alta (7.5) | 0.39% | — | Checkpoint Gaia PortalAI | 22/7/2026 | 24/7/2026 | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. | |
| Pendiente de análisis | Crítica (9.1) | 1.0% | — | Checkpoint Security ManagementAICheckpoint Multi-domain Security ManagementAI | 22/7/2026 | 24/7/2026 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation… |