Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.35% | — | Jetbrains Teamcity | 30/9/2026 | 2/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | |
| En análisis | Alta (8.8) | 0.46% | — | Jetbrains TeamcityAI | 30/9/2026 | 1/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | |
| En análisis | Alta (8.8) | 0.43% | — | Jetbrains TeamcityAI | 30/9/2026 | 1/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Jetbrains Teamcity | 27/7/2026 | 6/8/2026 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | |
| En análisis | Crítica (9.1) | 0.66% | — | Jetbrains TeamcityAI | 23/7/2026 | 24/7/2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | |
| Analizada | Crítica (10) | 0.66% | — | Jetbrains Teamcity | 23/7/2026 | 11/8/2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | |
| Analizada | Alta (8.1) | 0.35% | — | Jetbrains Teamcity | 10/7/2026 | 14/7/2026 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | |
| Analizada | Media (6.1) | 0.34% | — | Jetbrains Teamcity | 10/7/2026 | 13/7/2026 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | |
| Analizada | Media (5.4) | 0.32% | — | Jetbrains Teamcity | 10/7/2026 | 10/7/2026 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | |
| Analizada | Alta (8.8) | 0.49% | — | Jetbrains Teamcity | 10/7/2026 | 14/7/2026 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | |
| Analizada | Media (4.8) | 0.29% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | |
| Analizada | Media (6.1) | 0.23% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | |
| Analizada | Media (4.3) | 0.29% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | |
| Analizada | Media (4.3) | 0.92% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | |
| Analizada | Media (6.5) | 0.29% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin | |
| Analizada | Media (6.1) | 0.30% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | |
| Analizada | Alta (7.6) | 0.31% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | |
| Analizada | Alta (8.8) | 0.60% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | |
| Analizada | Alta (7.5) | 0.39% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | |
| Analizada | Alta (8.2) | 0.35% | — | Jetbrains Teamcity | 29/5/2026 | 22/7/2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | |
| Analizada | Alta (7.5) | 0.34% | — | Jetbrains Teamcity | 11/5/2026 | 17/6/2026 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access | |
| Analizada | Baja (2.3) | 0.17% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk | |
| Analizada | Media (4.3) | 0.26% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations | |
| Analizada | Media (6.1) | 0.29% | — | Jetbrains Teamcity | 25/2/2026 | 17/6/2026 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow |