Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.44% | — | Jetbrains Intellij Idea | 30/4/2026 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server | |
| Analizada | Crítica (9.8) | 0.35% | — | Jetbrains Junie | 17/4/2026 | 17/6/2026 | In JetBrains Junie before 252.549.29 command execution was possible via malicious project file | |
| Analizada | Alta (7.2) | 0.54% | — | Jetbrains Youtrack | 17/4/2026 | 17/6/2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass | |
| Analizada | Media (5.7) | 0.15% | — | Jetbrains Datalore | 13/3/2026 | 17/6/2026 | In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings | |
| Analizada | Media (6.8) | 0.28% | — | Jetbrains HUB | 11/3/2026 | 17/6/2026 | In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled | |
| Analizada | Baja (2.3) | 0.17% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk | |
| Analizada | Media (4.3) | 0.26% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations | |
| Analizada | Media (6.1) | 0.29% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow | |
| Analizada | Media (5.3) | 0.35% | — | Jetbrains Youtrack | 25/2/2026 | 17/6/2026 | In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint | |
| Analizada | Crítica (9.8) | 0.65% | — | Jetbrains HUB | 9/2/2026 | 17/6/2026 | In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible | |
| Analizada | Media (6.1) | 0.30% | — | Jetbrains Pycharm | 9/2/2026 | 17/6/2026 | In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible | |
| Analizada | Media (6.5) | 1.3% | — | Jetbrains Youtrack | 9/2/2026 | 17/6/2026 | In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs | |
| Analizada | Media (5.4) | 0.11% | — | Jetbrains Intellij Idea | 16/12/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH | |
| Analizada | Media (6.1) | 0.21% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page | |
| Analizada | Media (6.5) | 0.21% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token | |
| Analizada | Media (6.1) | 0.20% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab | |
| Analizada | Media (6.1) | 4.2% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup | |
| Analizada | Baja (2.7) | 0.24% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test | |
| Analizada | Media (4.8) | 0.19% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page | |
| Analizada | Baja (2.7) | 0.21% | — | Jetbrains Teamcity | 16/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration | |
| Analizada | Alta (7.5) | 0.80% | — | Jetbrains Teamcity | 11/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 path traversal was possible via file upload | |
| Analizada | Media (5.4) | 0.49% | — | Jetbrains Teamcity | 11/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute | |
| Analizada | Media (5.3) | 0.22% | — | Jetbrains Teamcity | 11/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata | |
| Analizada | Baja (3.1) | 0.17% | — | Jetbrains Teamcity | 11/12/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure | |
| Modificada | Baja (3.7) | 0.21% | — | Jetbrains Youtrack | 11/11/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit |