Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.79% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page | |
| Analizada | Media (4.3) | 0.22% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration | |
| Analizada | Media (4.3) | 0.22% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies | |
| Analizada | Crítica (9.4) | 0.29% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows | |
| Analizada | Crítica (9.8) | 0.18% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions | |
| Analizada | Alta (7.5) | 0.13% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration | |
| Analizada | Alta (8.8) | 0.16% | — | Jetbrains Teamcity | 28/7/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow | |
| Analizada | Media (6.1) | 0.26% | — | Jetbrains Youtrack | 28/7/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions | |
| Analizada | Alta (7.6) | 0.29% | — | Jetbrains Youtrack | 15/7/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible | |
| Aplazada | Alta (8.8) | 0.36% | — | Anthropic Claude CodeAIMicrosoft VscodeAIJetbrains IntellijAIJetbrains PycharmAI+1 | 24/6/2025 | 17/6/2026 | Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for… | |
| Analizada | Media (4.8) | 1.2% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible | |
| Analizada | Media (4.3) | 0.36% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions | |
| Analizada | Media (4.8) | 37% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible | |
| Analizada | Media (5.4) | 38% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible | |
| Analizada | Media (5.4) | 0.97% | — | Jetbrains Teamcity | 23/6/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible | |
| Analizada | Alta (7.5) | 0.41% | — | Jetbrains Youtrack | 20/5/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API | |
| Analizada | Media (6.1) | 0.26% | — | Jetbrains Teamcity | 20/5/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page | |
| Analizada | Media (5.4) | 0.73% | — | Jetbrains Teamcity | 20/5/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible | |
| Analizada | Media (5.4) | 0.73% | — | Jetbrains Teamcity | 20/5/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible | |
| Analizada | Media (5.4) | 2.7% | — | Jetbrains Teamcity | 20/5/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible | |
| Analizada | Media (5.3) | 0.37% | — | Jetbrains Youtrack | 20/5/2025 | 17/6/2026 | In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning | |
| Analizada | Media (6.1) | 63% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab | |
| Analizada | Crítica (9.8) | 0.55% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible | |
| Analizada | Media (6.5) | 1.0% | — | Jetbrains Teamcity | 25/4/2025 | 17/6/2026 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs | |
| Analizada | Alta (7.5) | 0.37% | — | Jetbrains Rider | 25/4/2025 | 17/6/2026 | In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session |