VYPR

by Jetbrains

Source repositories

CVEs (166)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2024-363670.020.22May 29, 2024In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
CVE-2025-264930.010.16Feb 11, 2025In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
CVE-2026-281960.000.00Feb 25, 2026In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
CVE-2026-281950.000.00Feb 25, 2026In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
CVE-2026-281940.000.00Feb 25, 2026In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
CVE-2025-682680.000.00Dec 16, 2025In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
CVE-2025-682670.000.00Dec 16, 2025In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token
CVE-2025-681660.000.00Dec 16, 2025In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
CVE-2025-681650.000.00Dec 16, 2025In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
CVE-2025-681640.000.00Dec 16, 2025In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
CVE-2025-681630.000.00Dec 16, 2025In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
CVE-2025-681620.000.00Dec 16, 2025In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
CVE-2025-677420.000.00Dec 11, 2025In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
CVE-2025-677410.000.00Dec 11, 2025In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
CVE-2025-677400.000.00Dec 11, 2025In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
CVE-2025-677390.000.00Dec 11, 2025In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
CVE-2025-594570.000.00Sep 17, 2025In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
CVE-2025-594560.000.00Sep 17, 2025In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
CVE-2025-594550.000.00Sep 17, 2025In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
CVE-2025-577340.000.00Aug 20, 2025In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files

Page 2 of 9