Filtered by vendor Jetbrains Subscriptions
Total 381 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-29927 1 Jetbrains 1 Teamcity 2024-08-03 4.6 Medium
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
CVE-2022-29929 1 Jetbrains 1 Teamcity 2024-08-03 3.7 Low
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
CVE-2022-29930 1 Jetbrains 1 Ktor 2024-08-03 8.7 High
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
CVE-2022-29814 1 Jetbrains 1 Intellij Idea 2024-08-03 6.9 Medium
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
CVE-2022-29821 1 Jetbrains 1 Pycharm 2024-08-03 6.9 Medium
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
CVE-2022-29819 1 Jetbrains 1 Intellij Idea 2024-08-03 6.9 Medium
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
CVE-2022-29817 1 Jetbrains 1 Intellij Idea 2024-08-03 3.9 Low
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
CVE-2022-29813 1 Jetbrains 1 Intellij Idea 2024-08-03 6.9 Medium
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
CVE-2022-29811 1 Jetbrains 1 Hub 2024-08-03 6.1 Medium
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
CVE-2022-29816 1 Jetbrains 1 Intellij Idea 2024-08-03 2.8 Low
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
CVE-2022-29812 1 Jetbrains 1 Intellij Idea 2024-08-03 2.3 Low
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
CVE-2022-29820 1 Jetbrains 1 Pycharm 2024-08-03 3 Low
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
CVE-2022-29815 1 Jetbrains 1 Intellij Idea 2024-08-03 6.9 Medium
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
CVE-2022-29818 1 Jetbrains 1 Intellij Idea 2024-08-03 3.9 Low
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
CVE-2022-29035 1 Jetbrains 1 Ktor 2024-08-03 3.3 Low
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
CVE-2022-28649 1 Jetbrains 1 Youtrack 2024-08-03 4.6 Medium
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
CVE-2022-28648 1 Jetbrains 1 Youtrack 2024-08-03 5.7 Medium
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
CVE-2022-28650 1 Jetbrains 1 Youtrack 2024-08-03 7.3 High
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
CVE-2022-28651 1 Jetbrains 1 Intellij Idea 2024-08-03 8.4 High
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
CVE-2022-25262 1 Jetbrains 1 Hub 2024-08-03 9.8 Critical
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.