Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
14.241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.20% | — | Jetbrains Youtrack | 30/9/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed | |
| Analizada | Baja (2.7) | 0.23% | — | Jetbrains Youtrack | 30/9/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates | |
| Analizada | Media (5.9) | 0.29% | — | Jetbrains Youtrack | 30/9/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters | |
| Analizada | Media (6.5) | 0.23% | — | Jetbrains HUB | 30/9/2026 | 2/10/2026 | In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | |
| Analizada | Media (6.5) | 0.10% | — | Jetbrains Rider | 30/9/2026 | 2/10/2026 | In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | |
| Analizada | Baja (2.7) | 0.23% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | |
| Analizada | Media (6.1) | 0.19% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | |
| Analizada | Alta (7.1) | 0.21% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | |
| Analizada | Media (5.4) | 0.18% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | |
| Analizada | Media (4.3) | 0.19% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | |
| Analizada | Media (4.3) | 0.65% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | |
| Analizada | Media (4.3) | 0.21% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | |
| Analizada | Alta (7.8) | 0.13% | — | Jetbrains Intellij Idea | 30/9/2026 | 2/10/2026 | In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects | |
| Analizada | Crítica (9.8) | 0.35% | — | Jetbrains Teamcity | 30/9/2026 | 2/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | |
| Analizada | Alta (8.8) | 0.47% | — | Jetbrains Teamcity | 30/9/2026 | 6/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | |
| Analizada | Alta (8.8) | 0.44% | — | Jetbrains Teamcity | 30/9/2026 | 6/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | |
| Aplazada | Media (5.3) | 0.20% | — | Paid Member SubscriptionsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Omnisend Newsletters Email Marketing SMS AND PopupsAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. | |
| Aplazada | Crítica (9) | 0.46% | — | Acymailing Smtp NewsletterAI | 30/9/2026 | 30/9/2026 | Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Longtailvideo JW PlayerAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | |
| Aplazada | Baja (2.7) | 0.23% | — | Brainstormforce AstraAI | 30/9/2026 | 30/9/2026 | Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. | |
| Aplazada | Alta (8.6) | 1.8% | — | Zosmaai Pi-llm-wikiAI | 30/9/2026 | 30/9/2026 | A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may… | |
| Aplazada | Media (5.3) | 0.19% | — | ZTE U30 AIRAI | 30/9/2026 | 30/9/2026 | There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information. |