VYPR

Vendor CVEs

Jetbrains

All CVEs

603 total · sorted by risk
  • CVE-2026-28195MedFeb 25, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

  • CVE-2026-28194MedFeb 25, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

  • CVE-2025-64684MedNov 10, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

  • CVE-2025-57734MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files

  • CVE-2025-54533MedJul 28, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

  • CVE-2025-54532MedJul 28, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

  • CVE-2025-52878MedJun 23, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions

  • CVE-2025-47854MedMay 20, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page

  • CVE-2025-47850MedMay 20, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

  • CVE-2025-46432MedApr 25, 2025
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs

  • CVE-2025-31139MedMar 27, 2025
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log

  • CVE-2025-24460MedJan 21, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool

  • CVE-2024-56350MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects

  • CVE-2024-56348MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents

  • CVE-2024-54157MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector

  • CVE-2024-50573MedOct 28, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services

  • CVE-2024-47161MedOct 8, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

  • CVE-2024-47160MedSep 19, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

  • CVE-2024-47159MedSep 19, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

  • CVE-2024-38504MedJun 18, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

  • CVE-2024-28173MedMar 6, 2024
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed

  • CVE-2024-24936MedFeb 6, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

  • CVE-2023-50871MedDec 15, 2023
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed

  • CVE-2023-50870MedDec 15, 2023
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible

  • CVE-2023-39174MedJul 25, 2023
    risk 0.28cvss 4.3epss 0.02

    In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers

  • CVE-2023-38067MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log

  • CVE-2023-38064MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log

  • CVE-2023-38062MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations

  • CVE-2023-34223MedMay 31, 2023
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases

  • CVE-2023-34219MedMay 31, 2023
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API

  • CVE-2022-24343MedFeb 25, 2022
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

  • CVE-2021-37554MedAug 6, 2021
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

  • CVE-2021-25774MedFeb 3, 2021
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.

  • CVE-2021-25771MedFeb 3, 2021
    risk 0.28cvss 4.3epss 0.02

    In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.

  • CVE-2020-27628MedNov 16, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.

  • CVE-2020-15826MedAug 8, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

  • CVE-2020-7908MedJan 30, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.

  • CVE-2020-5207MedJan 27, 2020
    risk 0.28cvss 5.4epss 0.01

    In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.

  • CVE-2019-18365MedOct 31, 2019
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.

  • CVE-2019-14956MedOct 2, 2019
    risk 0.28cvss 4.3epss 0.01

    JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.

  • CVE-2019-12846MedJul 3, 2019
    risk 0.28cvss 4.3epss 0.01

    A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.

  • CVE-2025-64457MedNov 10, 2025
    risk 0.27cvss 4.2epss 0.00

    In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

  • CVE-2025-59455MedSep 17, 2025
    risk 0.27cvss 4.2epss 0.00

    In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition

  • CVE-2025-42921MedApr 17, 2025
    risk 0.27cvss 4.2epss 0.00

    In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin

  • CVE-2025-29932MedMar 25, 2025
    risk 0.27cvss 4.1epss 0.00

    In JetBrains GoLand before 2025.1 an XXE during debugging was possible

  • CVE-2024-54156MedDec 4, 2024
    risk 0.27cvss 4.2epss 0.00

    In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

  • CVE-2024-49580MedOct 17, 2024
    risk 0.27cvss 5.3epss 0.00

    In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure

  • CVE-2024-47162MedSep 19, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

  • CVE-2024-39878MedJul 1, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

  • CVE-2024-31140MedMar 28, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

Page 10 of 13