Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2022-24331
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
Teamcity
2021.4+
HIGH 7.5
CVE-2022-24327
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
Hub
2021.1.13890+
MEDIUM 6.5
CVE-2022-24328
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
Hub
2021.1.13956+
MEDIUM 6.1
CVE-2022-24330
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
Teamcity
2021.2.1+
MEDIUM 5.3
CVE-2022-24329
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
Kotlin
1.6.0+
CRITICAL 9.8
CVE-2021-43202
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
Teamcity
2021.1.3+
HIGH 7.5
CVE-2021-43180
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
Hub
2021.1.13690+
HIGH 7.5
CVE-2021-43182
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
Hub
2021.1.13415+
MEDIUM 6.1
CVE-2021-43181
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
Hub
2021.1.13690+
HIGH 7.5
CVE-2021-43203
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
Ktor
1.6.4+
MEDIUM 5.3
CVE-2021-43201
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
Teamcity
2021.1.3+
CRITICAL 9.8
CVE-2021-43193
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
Teamcity
2021.1.2+
CRITICAL 9.8
CVE-2021-43200
In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
Teamcity
2021.2+
HIGH 7.5
CVE-2021-43196
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.
Teamcity
2021.1+
HIGH 7.3
CVE-2021-43188
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
Youtrack Mobile
2021.2+
HIGH 7.3
CVE-2021-43189
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
Youtrack Mobile
2021.2+
MEDIUM 6.1
CVE-2021-43197
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
Teamcity
2021.1.2+
MEDIUM 5.4
CVE-2021-43186
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
Youtrack
2021.3.24402+
MEDIUM 5.4
CVE-2021-43198
In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
Teamcity
2021.1.2+
MEDIUM 5.3
CVE-2021-43187
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
Youtrack Mobile
2021.2+
MEDIUM 5.3
CVE-2021-43190
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.
Youtrack Mobile
2021.2+
MEDIUM 5.3
CVE-2021-43191
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
Youtrack Mobile
2021.2+
MEDIUM 5.3
CVE-2021-43192
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
Youtrack Mobile
2021.2+
MEDIUM 5.3
CVE-2021-43194
In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
Teamcity
2021.1.2+
MEDIUM 5.3
CVE-2021-43195
In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.
Teamcity
2021.1.2+
MEDIUM 5.3
CVE-2021-43199
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
Teamcity
2021.1.2.+
CRITICAL 9.8
CVE-2021-43183
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
Hub
2021.1.13690+
CRITICAL 9.8
CVE-2021-43185
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
Youtrack
2021.3.23639+
MEDIUM 5.4
CVE-2021-43184
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
Youtrack
2021.3.21051+
CRITICAL 9.8
CVE-2021-37544
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
Teamcity
2020.2.4+