Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2021-26310
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
Teamcity
2020.2.2.85899+
HIGH 7.5
CVE-2021-30006
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
Intellij Idea
2020.3.3+
HIGH 7.5
CVE-2021-30504
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
Intellij Idea
2021.1+
HIGH 7.5
CVE-2021-31901
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
Hub
2021.1.13079+
HIGH 7.5
CVE-2021-31902
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
Youtrack
2020.6.6600+
HIGH 7.5
CVE-2021-31905
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
Youtrack
2020.6.8801+
MEDIUM 6.1
CVE-2021-31903
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
Youtrack
2021.1.9819+
MEDIUM 6.1
CVE-2021-31904
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
Teamcity
2020.2.2+
MEDIUM 5.4
CVE-2021-27733
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
Youtrack
2020.6.6441+
MEDIUM 5.3
CVE-2021-31900
In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.
Code With Me
2021.1+
MEDIUM 5.3
CVE-2021-25764
In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.
Phpstorm
2020.3+
CRITICAL 9.8
CVE-2021-25770
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
Youtrack
2020.5.3123+
HIGH 7.5
CVE-2021-25769
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
Youtrack
2020.4.6808+
HIGH 7.5
CVE-2021-25776
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
Teamcity
2020.2+
MEDIUM 6.1
CVE-2021-25773
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
Teamcity
2020.2+
MEDIUM 5.3
CVE-2021-25767
In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.
Youtrack
2020.6.1767+
MEDIUM 5.3
CVE-2021-25768
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
Youtrack
2020.4.4701+
MEDIUM 5.3
CVE-2021-25772
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
Teamcity
2020.2.2+
MEDIUM 5.3
CVE-2021-25777
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
Teamcity
2020.2.1+
MEDIUM 5.3
CVE-2021-25778
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
Teamcity
2020.2.1+
HIGH 8.8
CVE-2021-25765
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
Youtrack
2020.4.4701+
HIGH 7.8
CVE-2021-25758
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
Intellij Idea
2020.3+
HIGH 7.5
CVE-2020-35667
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
Teamcity
2020.2.85695+
MEDIUM 6.5
CVE-2021-25759
In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.
Hub
2020.1.12629+
MEDIUM 6.1
CVE-2021-25757
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
Hub
2020.1.12629+
MEDIUM 5.3
CVE-2021-25756
In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.
Intellij Idea
2020.2+
MEDIUM 5.3
CVE-2021-25760
In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.
Hub
2020.1.12669+
MEDIUM 5.3
CVE-2021-25761
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
Ktor
1.5.0+
MEDIUM 5.3
CVE-2021-25762
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
Ktor
1.4.3+
MEDIUM 5.3
CVE-2021-25763
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
Ktor
1.4.2+