Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2025-54537
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
Teamcity
2025.07+
CRITICAL 9.8
CVE-2025-54530
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
Teamcity
2025.07+
CRITICAL 9.4
CVE-2025-54531
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
Teamcity
2025.07+
HIGH 7.5
CVE-2025-54529
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
Teamcity
2025.07+
HIGH 8.8
CVE-2025-54528
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
Teamcity
2025.07+
MEDIUM 6.1
CVE-2025-54527
In JetBrains YouTrack before 2025.2.86935,
2025.2.87167,
2025.3.87341,
2025.3.87344 improper iframe configuration in widget sandbox allows popups …
Youtrack
2025.2.86935 / 2025.2.87167+
HIGH 7.6
CVE-2025-53959
In JetBrains YouTrack before 2025.2.86069,
2024.3.85077,
2025.1.86199 email spoofing via an administrative API was possible
Youtrack
2024.3.85077 / 2025.1.86199+
MEDIUM 5.4
CVE-2025-52875
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
Teamcity
2025.03.3+
MEDIUM 5.4
CVE-2025-52876EPSS 17%
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
Teamcity
2025.03.3+
HIGH 7.5
CVE-2025-48391
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
Youtrack
2025.1.76253+
MEDIUM 6.1
CVE-2025-47854
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
Teamcity
2025.03.2+
MEDIUM 5.4
CVE-2025-47851
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
Teamcity
2025.03.2+
MEDIUM 5.4
CVE-2025-47852
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
Teamcity
2025.03.2+
MEDIUM 5.4
CVE-2025-47853
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
Teamcity
2025.03.2+
MEDIUM 5.3
CVE-2025-47850
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
Youtrack
2025.1.74704+
CRITICAL 9.8
CVE-2025-46433
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
Teamcity
2025.03.1+
MEDIUM 6.5
CVE-2025-46432
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
Teamcity
2025.03.1+
MEDIUM 6.1
CVE-2025-46618EPSS 59%
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
Teamcity
2025.03.1+
HIGH 7.5
CVE-2025-43016
In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session
Rider
2025.1.2+
MEDIUM 6.5
CVE-2025-43014
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
Toolbox
2.6+
MEDIUM 6.5
CVE-2025-43015
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
Rubymine
2025.1+
CRITICAL 9.8
CVE-2025-43012
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
Toolbox
2.6+
HIGH 7.5
CVE-2025-43013
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
Toolbox
2.6+
MEDIUM 6.5
CVE-2025-42921
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
Toolbox
2.6+
HIGH 7.5
CVE-2025-31141
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
Teamcity
2025.03+
MEDIUM 6.5
CVE-2025-31139
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
Teamcity
2025.03+
MEDIUM 6.1
CVE-2025-31140EPSS 27%
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
Teamcity
2025.03+
MEDIUM 5.3
CVE-2025-29932
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
Goland
2025.1+
MEDIUM 5.3
CVE-2025-29904
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
Ktor
3.1.1+
HIGH 7.8
CVE-2025-29903
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
Runtime
21.0.6b872.80+