Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.22% | — | Jetbrains Youtrack | 10/11/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure | |
| Analizada | Alta (7.5) | 0.31% | — | Jetbrains Youtrack | 10/11/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form | |
| Analizada | Alta (7.5) | 0.20% | — | Jetbrains HUB | 10/11/2025 | 17/6/2026 | In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API | |
| Analizada | Baja (3.7) | 0.16% | — | Jetbrains HUB | 10/11/2025 | 17/6/2026 | In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit | |
| Analizada | Baja (3.7) | 0.19% | — | Jetbrains HUB | 10/11/2025 | 17/6/2026 | In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations | |
| Analizada | Alta (7.8) | 0.09% | — | Jetbrains Resharper | 10/11/2025 | 17/6/2026 | In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation | |
| Analizada | Alta (7) | 0.09% | — | Jetbrains DottraceJetbrains ResharperJetbrains Rider | 10/11/2025 | 25/9/2026 | In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition | |
| Analizada | Crítica (9.8) | 0.48% | — | Jetbrains Junie | 17/9/2025 | 17/6/2026 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation | |
| Analizada | Alta (7.7) | 0.83% | — | Jetbrains Teamcity | 17/9/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows | |
| Analizada | Media (5.5) | 14% | — | Jetbrains Teamcity | 17/9/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload | |
| Analizada | Media (4.2) | 0.42% | — | Jetbrains Teamcity | 17/9/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition | |
| Analizada | Alta (7.5) | 0.22% | — | Jetbrains Junie | 28/8/2025 | 25/9/2026 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function | |
| Analizada | Alta (8.8) | 0.29% | — | Jetbrains IDE Services | 28/8/2025 | 25/9/2026 | In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves | |
| Analizada | Media (6.5) | 0.80% | — | Jetbrains Teamcity | 20/8/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files | |
| Analizada | Baja (3.8) | 0.28% | — | Jetbrains Teamcity | 20/8/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content | |
| Analizada | Media (6.3) | 0.12% | — | Jetbrains Teamcity | 20/8/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership | |
| Analizada | Media (5.4) | 0.28% | — | Jetbrains Youtrack | 20/8/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content | |
| Analizada | Media (4.6) | 0.43% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature | |
| Analizada | Alta (7.3) | 0.13% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start | |
| Analizada | Media (6.5) | 0.25% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files | |
| Analizada | Alta (7.5) | 0.20% | — | Jetbrains Intellij Idea | 20/8/2025 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference | |
| Analizada | Media (5.5) | 0.26% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command | |
| Analizada | Media (5.5) | 0.26% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots | |
| Analizada | Alta (8.8) | 0.16% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint | |
| Analizada | Alta (7.5) | 0.18% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms |