Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2021-37549 In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient. Youtrack 2021.1.11111+ Fix from $2,3002021-08-06 HIGH 8.8 CVE-2021-37543 In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects. Rubymine 2021.1.1+ Fix from $1,9502021-08-06 HIGH 7.5 CVE-2021-37545 In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made. Teamcity 2021.1+ Fix from $1,9502021-08-06 HIGH 7.5 CVE-2021-37548 In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS. Teamcity 2021.1+ Fix from $1,9502021-08-06 HIGH 7.5 CVE-2021-37550 In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. Youtrack 2021.2.16363+ Fix from $1,9502021-08-06 HIGH 7.5 CVE-2021-37553 In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. Youtrack 2021.2.16363+ Fix from $1,9502021-08-06 MEDIUM 6.1 CVE-2021-37542 In JetBrains TeamCity before 2020.2.3, XSS was possible. Teamcity 2020.2.3+ Fix from $1,6002021-08-06 MEDIUM 5.4 CVE-2021-37552 In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. Youtrack 2021.2.17925+ Fix from $1,6002021-08-06 MEDIUM 5.3 CVE-2021-37546 In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. Teamcity 2021.1+ Fix from $1,6002021-08-06 MEDIUM 5.3 CVE-2021-37547 In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made. Teamcity 2020.2.4+ Fix from $1,6002021-08-06 MEDIUM 5.3 CVE-2021-37551 In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. Youtrack 2021.2.16363+ Fix from $1,6002021-08-06 CRITICAL 9.8 CVE-2021-36209 In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset. Hub 2021.1.13389+ Fix from $2,3002021-08-06 MEDIUM 6.5 CVE-2021-37540 In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used. Hub 2021.1.13262+ Fix from $1,6002021-08-06 MEDIUM 6.1 CVE-2021-37541 In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. Hub 2021.1.13402+ Fix from $1,6002021-08-06 CRITICAL 9.8 CVE-2021-31897 In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects. Webstorm 2021.1+ Fix from $2,3002021-05-11 CRITICAL 9.8 CVE-2021-31914 In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. Teamcity 2020.2.4+ Fix from $2,3002021-05-11 CRITICAL 9.8 CVE-2021-31915 In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. Teamcity 2020.2.4+ Fix from $2,3002021-05-11 HIGH 8.8 CVE-2021-31912 In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. Teamcity 2020.2.3+ Fix from $1,9502021-05-11 HIGH 7.5 CVE-2021-30482 In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly Upsource 2020.1.1883+ Fix from $1,9502021-05-11 HIGH 7.5 CVE-2021-31898 In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. Webstorm 2021.1+ Fix from $1,9502021-05-11 HIGH 7.5 CVE-2021-31910 In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. Teamcity 2020.2.3+ Fix from $1,9502021-05-11 HIGH 7.5 CVE-2021-31913 In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange. Teamcity 2020.2.3+ Fix from $1,9502021-05-11 MEDIUM 6.1 CVE-2021-31911 In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. Teamcity 2020.2.3+ Fix from $1,6002021-05-11 CRITICAL 9.8 CVE-2021-31909 In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible. Teamcity 2020.2.3+ Fix from $2,3002021-05-11 MEDIUM 5.4 CVE-2021-31908 In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages. Teamcity 2020.2.3+ Fix from $1,6002021-05-11 MEDIUM 5.4 CVE-2021-3315 In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible. Teamcity 2020.2.2+ Fix from $1,6002021-05-11 MEDIUM 5.3 CVE-2021-31907 In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly. Teamcity 2020.2.2+ Fix from $1,6002021-05-11 HIGH 8.8 CVE-2021-31899 In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode. Code With Me 2021.1+ Fix from $1,9502021-05-11 HIGH 7.8 CVE-2021-29263 In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS. Intellij Idea 2020.3.3+ Fix from $1,9502021-05-11 HIGH 7.8 CVE-2021-30005 In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS. Pycharm 2020.3.4+ Fix from $1,9502021-05-11