Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Teamcity MEDIUM 5.5
CVE-2025-54537

In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

Fix: 2025.07+
Fix from $1,600 2025-07-28
Teamcity CRITICAL 9.8
CVE-2025-54530

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

Fix: 2025.07+
Fix from $2,300 2025-07-28
Teamcity CRITICAL 9.4
CVE-2025-54531

In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

Fix: 2025.07+
Fix from $2,300 2025-07-28
Teamcity HIGH 7.5
CVE-2025-54529

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

Fix: 2025.07+
Fix from $1,950 2025-07-28
Teamcity HIGH 8.8
CVE-2025-54528

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

Fix: 2025.07+
Fix from $1,950 2025-07-28
Youtrack MEDIUM 6.1
CVE-2025-54527

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups …

Fix: 2025.2.86935 / 2025.2.87167+
Fix from $1,600 2025-07-28
Youtrack HIGH 7.6
CVE-2025-53959

In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible

Fix: 2024.3.85077 / 2025.1.86199+
Fix from $1,950 2025-07-15
Teamcity MEDIUM 5.4
CVE-2025-52875

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

Fix: 2025.03.3+
Fix from $1,600 2025-06-23
Teamcity MEDIUM 5.4
CVE-2025-52876EPSS 17%

In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

Fix: 2025.03.3+
Fix from $1,600 2025-06-23
Youtrack HIGH 7.5
CVE-2025-48391

In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

Fix: 2025.1.76253+
Fix from $1,950 2025-05-20
Teamcity MEDIUM 6.1
CVE-2025-47854

In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page

Fix: 2025.03.2+
Fix from $1,600 2025-05-20
Teamcity MEDIUM 5.4
CVE-2025-47851

In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible

Fix: 2025.03.2+
Fix from $1,600 2025-05-20
Teamcity MEDIUM 5.4
CVE-2025-47852

In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible

Fix: 2025.03.2+
Fix from $1,600 2025-05-20
Teamcity MEDIUM 5.4
CVE-2025-47853

In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible

Fix: 2025.03.2+
Fix from $1,600 2025-05-20
Youtrack MEDIUM 5.3
CVE-2025-47850

In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

Fix: 2025.1.74704+
Fix from $1,600 2025-05-20
Teamcity CRITICAL 9.8
CVE-2025-46433

In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

Fix: 2025.03.1+
Fix from $2,300 2025-04-25
Teamcity MEDIUM 6.5
CVE-2025-46432

In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs

Fix: 2025.03.1+
Fix from $1,600 2025-04-25
Teamcity MEDIUM 6.1
CVE-2025-46618EPSS 59%

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

Fix: 2025.03.1+
Fix from $1,600 2025-04-25
Rider HIGH 7.5
CVE-2025-43016

In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

Fix: 2025.1.2+
Fix from $1,950 2025-04-25
Toolbox MEDIUM 6.5
CVE-2025-43014

In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation

Fix: 2.6+
Fix from $1,600 2025-04-17
Rubymine MEDIUM 6.5
CVE-2025-43015

In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces

Fix: 2025.1+
Fix from $1,600 2025-04-17
Toolbox CRITICAL 9.8
CVE-2025-43012

In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

Fix: 2.6+
Fix from $2,300 2025-04-17
Toolbox HIGH 7.5
CVE-2025-43013

In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

Fix: 2.6+
Fix from $1,950 2025-04-17
Toolbox MEDIUM 6.5
CVE-2025-42921

In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin

Fix: 2.6+
Fix from $1,600 2025-04-17
Teamcity HIGH 7.5
CVE-2025-31141

In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page

Fix: 2025.03+
Fix from $1,950 2025-03-27
Teamcity MEDIUM 6.5
CVE-2025-31139

In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log

Fix: 2025.03+
Fix from $1,600 2025-03-27
Teamcity MEDIUM 6.1
CVE-2025-31140EPSS 27%

In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page

Fix: 2025.03+
Fix from $1,600 2025-03-27
Goland MEDIUM 5.3
CVE-2025-29932

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

Fix: 2025.1+
Fix from $1,600 2025-03-25
Ktor MEDIUM 5.3
CVE-2025-29904

In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible

Fix: 3.1.1+
Fix from $1,600 2025-03-12
Runtime HIGH 7.8
CVE-2025-29903

In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible

Fix: 21.0.6b872.80+
Fix from $1,950 2025-03-12