Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2024-50577 In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings Youtrack 2024.3.47707+ Fix from $1,6002024-10-28 MEDIUM 6.1 CVE-2024-49579 In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests Youtrack 2024.3.47197+ Fix from $1,6002024-10-17 MEDIUM 5.3 CVE-2024-49580 In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure Ktor 3.0.0+ Fix from $1,6002024-10-17 MEDIUM 5.4 CVE-2024-48902 In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API Youtrack 2024.3.46677+ Fix from $1,6002024-10-10 MEDIUM 5.4 CVE-2024-47951 In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings Teamcity 2024.07.3+ Fix from $1,6002024-10-08 HIGH 7.5 CVE-2024-47948 In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups Teamcity 2024.07.3+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-47949EPSS 23% In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location Teamcity 2024.07.3+ Fix from $1,9502024-10-08 MEDIUM 6.5 CVE-2024-47161 In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API Teamcity 2024.07.3+ Fix from $1,6002024-10-08 MEDIUM 5.4 CVE-2024-47950 In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings Teamcity 2024.07.03+ Fix from $1,6002024-10-08 MEDIUM 5.3 CVE-2024-47160 In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible Youtrack 2024.3.44799+ Fix from $1,6002024-09-19 MEDIUM 5.3 CVE-2024-47162 In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page Youtrack 2024.3.44799+ Fix from $1,6002024-09-19 MEDIUM 6.1 CVE-2024-46970 In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible Intellij Idea 2024.1.0+ Fix from $1,6002024-09-16 MEDIUM 6.1 CVE-2024-43809 In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page Teamcity 2024.07.1+ Fix from $1,6002024-08-16 MEDIUM 5.4 CVE-2024-43807 In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page Teamcity 2024.07.1+ Fix from $1,6002024-08-16 MEDIUM 5.4 CVE-2024-43808 In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin Teamcity 2024.07.1+ Fix from $1,6002024-08-16 MEDIUM 5.4 CVE-2024-43810 In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin Teamcity 2024.07.1+ Fix from $1,6002024-08-16 HIGH 7.8 CVE-2024-43114 In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions Teamcity 2024.07.1+ Fix from $1,9502024-08-06 CRITICAL 9.8 CVE-2024-41827 In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration Teamcity 2024.07+ Fix from $2,3002024-07-22 HIGH 7.5 CVE-2024-41829 In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection Teamcity 2024.07+ Fix from $1,9502024-07-22 MEDIUM 6.5 CVE-2024-41828 In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time Teamcity 2024.07+ Fix from $1,6002024-07-22 MEDIUM 6.5 CVE-2024-41824 In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases Teamcity 2024.07+ Fix from $1,6002024-07-22 MEDIUM 5.4 CVE-2024-41825 In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab Teamcity 2024.07+ Fix from $1,6002024-07-22 MEDIUM 5.3 CVE-2024-39878 In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection Teamcity 2024.03.3+ Fix from $1,6002024-07-01 MEDIUM 5.3 CVE-2024-39879 In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings Teamcity 2024.03.3+ Fix from $1,6002024-07-01 HIGH 8.1 CVE-2024-38506 In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows Youtrack 2024.2.34646+ Fix from $1,9502024-06-18 MEDIUM 5.4 CVE-2024-38507 In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible Hub 2024.2.34646+ Fix from $1,6002024-06-18 HIGH 7.5 CVE-2024-38505 In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site Youtrack 2024.2.34646+ Fix from $1,9502024-06-18 MEDIUM 5.3 CVE-2024-38504 In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles Youtrack 2024.2.34646+ Fix from $1,6002024-06-18 HIGH 7.5 CVE-2024-37051 GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 202… Aqua 2023.1.3 / 2023.1.6+ Fix from $1,9502024-06-10 CRITICAL 9.8 CVE-2024-36470 In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases Teamcity 2022.04.7 / 2022.10.6+ Fix from $2,3002024-05-29