Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 5 respecto a la semana anterior
Críticas / altas1274▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
–

14.294 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (10)0.66%—Jetbrains Teamcity23/7/202611/8/2026
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
AnalizadaCrítica (9.8)0.48%—Jetbrains Intellij Idea23/7/202628/7/2026
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
AnalizadaAlta (8.6)0.39%—Jetbrains Intellij Idea23/7/202628/7/2026
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
AnalizadaCrítica (10)0.52%—Jetbrains Intellij Idea23/7/202628/7/2026
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
AnalizadaCrítica (10)0.48%—Jetbrains Intellij Idea23/7/202628/7/2026
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
AnalizadaAlta (7.8)0.18%—Jetbrains Intellij Idea23/7/202628/7/2026
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
AnalizadaMedia (6.1)0.25%—Jetbrains Intellij Idea23/7/202628/7/2026
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
AnalizadaAlta (8.4)0.19%—Jetbrains Phpstorm23/7/202628/7/2026
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
AnalizadaAlta (8.4)0.19%—Jetbrains Phpstorm23/7/202628/7/2026
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
AnalizadaAlta (7.8)0.18%—Jetbrains Webstorm23/7/202628/7/2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
AnalizadaAlta (8.4)0.19%—Jetbrains Webstorm23/7/202628/7/2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
AnalizadaAlta (8.4)0.19%—Jetbrains Webstorm23/7/202628/7/2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
AnalizadaAlta (8.4)0.19%—Jetbrains Webstorm23/7/202628/7/2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
AnalizadaAlta (7.8)0.21%—Jetbrains Goland23/7/202628/7/2026
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
AnalizadaAlta (7.8)0.21%—Jetbrains Goland23/7/202628/7/2026
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
AnalizadaMedia (5.7)0.85%—Jetbrains Goland23/7/202628/7/2026
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
AplazadaAlta (7.1)0.13%—MailpoetAI23/7/202623/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
AplazadaCrítica (9.1)0.50%—MailsterAI23/7/202623/7/2026
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
AplazadaCrítica (9.8)0.71%💥 PoCMountdev AI MCP ConnectorAI23/7/202623/7/2026
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an…
AplazadaMedia (6.5)0.45%—AI Copilot Content GeneratorAI23/7/202623/7/2026
The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
Pendiente de análisisAlta (8.8)0.46%—Redhat Openshift AIAIRedhat ODH DashboardAI23/7/202630/9/2026
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the…
AplazadaAlta (7.5)0.41%—Praison AI SEOAI23/7/202623/7/2026
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.
AplazadaMedia (6.3)0.44%—InvokeaiAI22/7/202623/7/2026
InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to…
Pendiente de análisisAlta (7.5)0.39%—Checkpoint Gaia PortalAI22/7/202624/7/2026
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
Pendiente de análisisCrítica (9.1)1.0%—Checkpoint Security ManagementAICheckpoint Multi-domain Security ManagementAI22/7/202624/7/2026
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation…