Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-26492 In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources Teamcity 2024.12.2+ Fix from $2,3002025-02-11 MEDIUM 6.1 CVE-2025-26493 In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab Teamcity 2024.12.2+ Fix from $1,6002025-02-11 HIGH 7.8 CVE-2025-23385 In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, an… Dottrace 16.43 / 2024.1.7+ Fix from $1,9502025-01-28 MEDIUM 6.5 CVE-2025-24461 In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint Teamcity Mitigation only Fix from $1,6002025-01-21 HIGH 8.8 CVE-2025-24456 In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping Hub 2024.3.55417+ Fix from $1,9502025-01-21 HIGH 7.8 CVE-2025-24458 In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration Youtrack 2024.3.55417+ Fix from $1,9502025-01-21 MEDIUM 6.1 CVE-2025-24459 In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page Teamcity 2024.12.1+ Fix from $1,6002025-01-21 MEDIUM 5.5 CVE-2025-24457 In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs Youtrack 2024.3.55417+ Fix from $1,6002025-01-21 HIGH 7.1 CVE-2024-56356 In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack Teamcity 2024.12+ Fix from $1,9502024-12-20 MEDIUM 6.5 CVE-2024-56353 In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies Teamcity 2024.12+ Fix from $1,6002024-12-20 MEDIUM 5.4 CVE-2024-56355 In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS Teamcity 2024.12+ Fix from $1,6002024-12-20 HIGH 8.8 CVE-2024-56351 In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles Teamcity 2024.12+ Fix from $1,9502024-12-20 MEDIUM 5.4 CVE-2024-56352 In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page Teamcity 2024.12+ Fix from $1,6002024-12-20 MEDIUM 5.3 CVE-2024-56349 In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs Teamcity 2024.12+ Fix from $1,6002024-12-20 CRITICAL 9.8 CVE-2024-54154 In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox Youtrack 2024.3.51866+ Fix from $2,3002024-12-04 MEDIUM 6.5 CVE-2024-54156 In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack Youtrack 2024.3.52635+ Fix from $1,6002024-12-04 MEDIUM 6.5 CVE-2024-54157 In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector Youtrack 2024.3.52635+ Fix from $1,6002024-12-04 MEDIUM 5.3 CVE-2024-54155 In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication Youtrack 2024.3.51866+ Fix from $1,6002024-12-04 MEDIUM 5.3 CVE-2024-54158 In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding Youtrack 2024.3.52635+ Fix from $1,6002024-12-04 MEDIUM 6.5 CVE-2024-54153 In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter Youtrack 2024.3.51866+ Fix from $1,6002024-12-04 HIGH 7.8 CVE-2024-52555 In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script Webstorm 2024.3.0+ Fix from $1,9502024-11-15 MEDIUM 6.1 CVE-2024-50579 In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible Youtrack 2024.3.47707+ Fix from $1,6002024-10-28 MEDIUM 5.4 CVE-2024-50578 In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page Youtrack 2024.3.47707+ Fix from $1,6002024-10-28 MEDIUM 5.4 CVE-2024-50580 In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule Youtrack 2024.3.47707+ Fix from $1,6002024-10-28 MEDIUM 5.4 CVE-2024-50581 In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag Youtrack 2024.3.47707+ Fix from $1,6002024-10-28 MEDIUM 5.4 CVE-2024-50582 In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements Youtrack 2024.3.47707+ Fix from $1,6002024-10-28 HIGH 7.5 CVE-2024-50574 In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality Youtrack 2024.3.47707+ Fix from $1,9502024-10-28 MEDIUM 6.1 CVE-2024-50575 In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API Youtrack 2024.3.47707+ Fix from $1,6002024-10-28 MEDIUM 5.4 CVE-2024-50573 In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services Hub 2024.3.47707+ Fix from $1,6002024-10-28 MEDIUM 5.4 CVE-2024-50576 In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest Youtrack 2024.3.47707+ Fix from $1,6002024-10-28