Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
1386 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.15% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration | |
| Analizada | Media (5.4) | 0.14% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications | |
| Analizada | Media (4.3) | 0.19% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs | |
| Analizada | Media (6.6) | 0.21% | — | Jetbrains Youtrack | 1/10/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes | |
| Analizada | Alta (8.1) | 0.22% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible | |
| Analizada | Media (6.5) | 0.68% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments | |
| Analizada | Media (6.5) | 0.20% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues | |
| En análisis | Alta (7.2) | 0.43% | — | Jetbrains YoutrackAI | 1/10/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links | |
| En análisis | Baja (2) | 0.14% | — | Jetbrains YoutrackAI | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible | |
| En análisis | Alta (7.1) | 0.28% | — | Jetbrains YoutrackAI | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues | |
| Analizada | Media (4.3) | 0.17% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible | |
| Analizada | Media (6.5) | 0.25% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials | |
| Analizada | Media (4.9) | 0.24% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | |
| Analizada | Crítica (9.8) | 0.28% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | |
| Analizada | Alta (7.5) | 0.22% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | |
| Analizada | Media (4.8) | 0.19% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible | |
| Analizada | Media (6.5) | 0.84% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template | |
| Analizada | Crítica (9.8) | 0.30% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | |
| Analizada | Media (4.9) | 0.29% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues | |
| Analizada | Baja (2.7) | 0.23% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects | |
| Analizada | Baja (2.7) | 0.17% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations | |
| Analizada | Media (4.3) | 0.20% | — | Jetbrains Youtrack | 30/9/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed | |
| Analizada | Baja (2.7) | 0.23% | — | Jetbrains Youtrack | 30/9/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates | |
| Analizada | Media (5.9) | 0.29% | — | Jetbrains Youtrack | 30/9/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters | |
| Analizada | Baja (2.7) | 0.23% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host |