VYPR

by Jetbrains

Source repositories

CVEs (166)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-577330.000.00Aug 20, 2025In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
CVE-2025-577320.000.00Aug 20, 2025In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
CVE-2025-545380.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
CVE-2025-545370.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
CVE-2025-545360.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
CVE-2025-545350.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
CVE-2025-545340.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
CVE-2025-545330.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
CVE-2025-545320.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
CVE-2025-545310.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
CVE-2025-545300.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
CVE-2025-545290.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
CVE-2025-545280.000.00Jul 28, 2025In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
CVE-2025-528790.000.00Jun 23, 2025In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
CVE-2025-528780.000.00Jun 23, 2025In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
CVE-2025-528770.000.00Jun 23, 2025In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
CVE-2025-528760.000.01Jun 23, 2025In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
CVE-2025-528750.000.00Jun 23, 2025In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
CVE-2025-478540.000.00May 20, 2025In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
CVE-2025-478530.000.00May 20, 2025In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible

Page 3 of 9