Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Youtrack MEDIUM 5.4
CVE-2024-50577

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings

Fix: 2024.3.47707+
Fix from $1,600 2024-10-28
Youtrack MEDIUM 6.1
CVE-2024-49579

In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

Fix: 2024.3.47197+
Fix from $1,600 2024-10-17
Ktor MEDIUM 5.3
CVE-2024-49580

In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure

Fix: 3.0.0+
Fix from $1,600 2024-10-17
Youtrack MEDIUM 5.4
CVE-2024-48902

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

Fix: 2024.3.46677+
Fix from $1,600 2024-10-10
Teamcity MEDIUM 5.4
CVE-2024-47951

In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

Fix: 2024.07.3+
Fix from $1,600 2024-10-08
Teamcity HIGH 7.5
CVE-2024-47948

In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

Fix: 2024.07.3+
Fix from $1,950 2024-10-08
Teamcity HIGH 7.5
CVE-2024-47949EPSS 23%

In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

Fix: 2024.07.3+
Fix from $1,950 2024-10-08
Teamcity MEDIUM 6.5
CVE-2024-47161

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

Fix: 2024.07.3+
Fix from $1,600 2024-10-08
Teamcity MEDIUM 5.4
CVE-2024-47950

In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

Fix: 2024.07.03+
Fix from $1,600 2024-10-08
Youtrack MEDIUM 5.3
CVE-2024-47160

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

Fix: 2024.3.44799+
Fix from $1,600 2024-09-19
Youtrack MEDIUM 5.3
CVE-2024-47162

In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

Fix: 2024.3.44799+
Fix from $1,600 2024-09-19
Intellij Idea MEDIUM 6.1
CVE-2024-46970

In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible

Fix: 2024.1.0+
Fix from $1,600 2024-09-16
Teamcity MEDIUM 6.1
CVE-2024-43809

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page

Fix: 2024.07.1+
Fix from $1,600 2024-08-16
Teamcity MEDIUM 5.4
CVE-2024-43807

In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page

Fix: 2024.07.1+
Fix from $1,600 2024-08-16
Teamcity MEDIUM 5.4
CVE-2024-43808

In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin

Fix: 2024.07.1+
Fix from $1,600 2024-08-16
Teamcity MEDIUM 5.4
CVE-2024-43810

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin

Fix: 2024.07.1+
Fix from $1,600 2024-08-16
Teamcity HIGH 7.8
CVE-2024-43114

In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

Fix: 2024.07.1+
Fix from $1,950 2024-08-06
Teamcity CRITICAL 9.8
CVE-2024-41827

In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration

Fix: 2024.07+
Fix from $2,300 2024-07-22
Teamcity HIGH 7.5
CVE-2024-41829

In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

Fix: 2024.07+
Fix from $1,950 2024-07-22
Teamcity MEDIUM 6.5
CVE-2024-41828

In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time

Fix: 2024.07+
Fix from $1,600 2024-07-22
Teamcity MEDIUM 6.5
CVE-2024-41824

In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

Fix: 2024.07+
Fix from $1,600 2024-07-22
Teamcity MEDIUM 5.4
CVE-2024-41825

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

Fix: 2024.07+
Fix from $1,600 2024-07-22
Teamcity MEDIUM 5.3
CVE-2024-39878

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

Fix: 2024.03.3+
Fix from $1,600 2024-07-01
Teamcity MEDIUM 5.3
CVE-2024-39879

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

Fix: 2024.03.3+
Fix from $1,600 2024-07-01
Youtrack HIGH 8.1
CVE-2024-38506

In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

Fix: 2024.2.34646+
Fix from $1,950 2024-06-18
Hub MEDIUM 5.4
CVE-2024-38507

In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible

Fix: 2024.2.34646+
Fix from $1,600 2024-06-18
Youtrack HIGH 7.5
CVE-2024-38505

In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

Fix: 2024.2.34646+
Fix from $1,950 2024-06-18
Youtrack MEDIUM 5.3
CVE-2024-38504

In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

Fix: 2024.2.34646+
Fix from $1,600 2024-06-18
Aqua HIGH 7.5
CVE-2024-37051

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 202…

Fix: 2023.1.3 / 2023.1.6+
Fix from $1,950 2024-06-10
Teamcity CRITICAL 9.8
CVE-2024-36470

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases

Fix: 2022.04.7 / 2022.10.6+
Fix from $2,300 2024-05-29