Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.52% | — | Jetbrains HUB | 19/6/2026 | 26/6/2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible | |
| Analizada | Alta (8.8) | 0.45% | — | Jetbrains Goland | 19/6/2026 | 26/6/2026 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | |
| Analizada | Crítica (9.8) | 0.61% | — | Jetbrains HUB | 19/6/2026 | 26/6/2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas | |
| Analizada | Media (6.5) | 0.30% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts | |
| Analizada | Media (6.1) | 0.25% | — | Jetbrains Pycharm | 29/5/2026 | 22/7/2026 | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible | |
| Analizada | Baja (3.3) | 0.14% | — | Jetbrains Intellij Idea | 29/5/2026 | 22/7/2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible | |
| Analizada | Alta (7.8) | 0.18% | — | Jetbrains Intellij Idea | 29/5/2026 | 22/7/2026 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin | |
| Analizada | Media (4.8) | 0.29% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | |
| Analizada | Media (6.1) | 0.23% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | |
| Analizada | Media (4.3) | 0.29% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | |
| Analizada | Media (4.3) | 0.92% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | |
| Analizada | Media (6.5) | 0.29% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin | |
| Analizada | Media (6.1) | 0.30% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | |
| Analizada | Alta (7.6) | 0.31% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | |
| Analizada | Alta (8.8) | 0.60% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | |
| Analizada | Alta (7.5) | 0.39% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | |
| Analizada | Alta (8.2) | 0.35% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | |
| Analizada | Alta (7.5) | 0.33% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests | |
| Analizada | Media (4.3) | 0.27% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages | |
| Analizada | Media (5.4) | 0.27% | — | Jetbrains Youtrack | 29/5/2026 | 22/7/2026 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | |
| Analizada | Alta (8.8) | 0.51% | — | Jetbrains Intellij Idea | 29/5/2026 | 22/7/2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account | |
| Analizada | Alta (7.8) | 0.68% | — | Jetbrains Intellij Idea | 29/5/2026 | 22/7/2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion | |
| Analizada | Alta (7.5) | 0.34% | — | Jetbrains Teamcity | 11/5/2026 | 17/6/2026 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access |