Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 75% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings | |
| Modificada | Media (6.1) | 0.38% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration | |
| Analizada | Alta (7.4) | 0.54% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter | |
| Modificada | Media (6.1) | 0.48% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 open redirect was possible on the login page | |
| Analizada | Media (6.5) | 0.43% | — | Jetbrains Teamcity | 28/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled | |
| Analizada | Alta (7.8) | 0.23% | — | Jetbrains Teamcity | 21/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process | |
| Analizada | Media (5.8) | 0.34% | — | Jetbrains Teamcity | 6/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly | |
| Analizada | Media (4.3) | 0.53% | — | Jetbrains Teamcity | 6/3/2024 | 17/6/2026 | In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed | |
| Analizada | Alta (7.3) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 4/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 4/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | |
| Modificada | Media (5.3) | 32% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | |
| Modificada | Media (5.3) | 0.74% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation | |
| Modificada | Media (5.4) | 0.36% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible | |
| Modificada | Media (5.3) | 0.31% | — | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Jetbrains Teamcity | 6/2/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible | |
| Modificada | Alta (8.8) | 0.32% | — | Jetbrains Teamcity | 15/12/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible | |
| Modificada | Media (5.4) | 1.0% | — | Jetbrains Teamcity | 19/9/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 19/9/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | |
| Modificada | Media (6.1) | 0.37% | — | Jetbrains Teamcity | 25/8/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration | |
| Modificada | Media (6.1) | 56% | — | Jetbrains Teamcity | 25/8/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | |
| Modificada | Media (5.4) | 0.36% | — | Jetbrains Teamcity | 25/8/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration | |
| Modificada | Media (6.1) | 1.0% | — | Jetbrains Teamcity | 25/7/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible | |
| Modificada | Alta (7.5) | 1.7% | — | Jetbrains Teamcity | 25/7/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers | |
| Modificada | Alta (8.8) | 0.40% | — | Jetbrains Teamcity | 25/7/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access | |
| Modificada | Media (6.5) | 0.50% | — | Jetbrains Teamcity | 12/7/2023 | 17/6/2026 | In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log |