Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2024-50577
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
Youtrack
2024.3.47707+
MEDIUM 6.1
CVE-2024-49579
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
Youtrack
2024.3.47197+
MEDIUM 5.3
CVE-2024-49580
In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
Ktor
3.0.0+
MEDIUM 5.4
CVE-2024-48902
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
Youtrack
2024.3.46677+
MEDIUM 5.4
CVE-2024-47951
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
Teamcity
2024.07.3+
HIGH 7.5
CVE-2024-47948
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
Teamcity
2024.07.3+
HIGH 7.5
CVE-2024-47949EPSS 23%
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
Teamcity
2024.07.3+
MEDIUM 6.5
CVE-2024-47161
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
Teamcity
2024.07.3+
MEDIUM 5.4
CVE-2024-47950
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
Teamcity
2024.07.03+
MEDIUM 5.3
CVE-2024-47160
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
Youtrack
2024.3.44799+
MEDIUM 5.3
CVE-2024-47162
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
Youtrack
2024.3.44799+
MEDIUM 6.1
CVE-2024-46970
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
Intellij Idea
2024.1.0+
MEDIUM 6.1
CVE-2024-43809
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
Teamcity
2024.07.1+
MEDIUM 5.4
CVE-2024-43807
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
Teamcity
2024.07.1+
MEDIUM 5.4
CVE-2024-43808
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
Teamcity
2024.07.1+
MEDIUM 5.4
CVE-2024-43810
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
Teamcity
2024.07.1+
HIGH 7.8
CVE-2024-43114
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
Teamcity
2024.07.1+
CRITICAL 9.8
CVE-2024-41827
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
Teamcity
2024.07+
HIGH 7.5
CVE-2024-41829
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
Teamcity
2024.07+
MEDIUM 6.5
CVE-2024-41828
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
Teamcity
2024.07+
MEDIUM 6.5
CVE-2024-41824
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
Teamcity
2024.07+
MEDIUM 5.4
CVE-2024-41825
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
Teamcity
2024.07+
MEDIUM 5.3
CVE-2024-39878
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
Teamcity
2024.03.3+
MEDIUM 5.3
CVE-2024-39879
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
Teamcity
2024.03.3+
HIGH 8.1
CVE-2024-38506
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows
Youtrack
2024.2.34646+
MEDIUM 5.4
CVE-2024-38507
In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible
Hub
2024.2.34646+
HIGH 7.5
CVE-2024-38505
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
Youtrack
2024.2.34646+
MEDIUM 5.3
CVE-2024-38504
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
Youtrack
2024.2.34646+
HIGH 7.5
CVE-2024-37051
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 202…
Aqua
2023.1.3 / 2023.1.6+
CRITICAL 9.8
CVE-2024-36470
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
Teamcity
2022.04.7 / 2022.10.6+