Filtered by vendor Jetbrains Subscriptions
Total 404 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-41825 1 Jetbrains 1 Teamcity 2024-08-07 4.6 Medium
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
CVE-2024-41826 1 Jetbrains 1 Teamcity 2024-08-07 3.5 Low
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
CVE-2024-41827 1 Jetbrains 1 Teamcity 2024-08-07 7.4 High
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
CVE-2024-41828 1 Jetbrains 1 Teamcity 2024-08-07 2.6 Low
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
CVE-2014-10036 1 Jetbrains 1 Teamcity 2024-08-06 N/A
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.
CVE-2015-1313 1 Jetbrains 1 Teamcity 2024-08-06 6.5 Medium
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.
CVE-2018-14878 1 Jetbrains 2 Dotpeek, Resharper Ultimate 2024-08-05 N/A
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.
CVE-2019-19704 1 Jetbrains 1 Upsource 2024-08-05 7.5 High
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
CVE-2019-19703 1 Jetbrains 1 Ktor 2024-08-05 6.1 Medium
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
CVE-2019-19389 1 Jetbrains 1 Ktor 2024-08-05 5.4 Medium
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
CVE-2019-18361 1 Jetbrains 1 Intellij Idea 2024-08-05 5.3 Medium
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.
CVE-2019-18365 1 Jetbrains 1 Teamcity 2024-08-05 4.3 Medium
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
CVE-2019-18412 1 Jetbrains 1 Idetalk 2024-08-05 7.5 High
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
CVE-2019-18360 1 Jetbrains 1 Hub 2024-08-05 5.3 Medium
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
CVE-2019-18368 1 Jetbrains 1 Toolbox 2024-08-05 7.3 High
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
CVE-2019-18362 1 Jetbrains 1 Mps 2024-08-05 5.3 Medium
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
CVE-2019-18364 1 Jetbrains 1 Teamcity 2024-08-05 9.8 Critical
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
CVE-2019-18367 1 Jetbrains 1 Teamcity 2024-08-05 5.3 Medium
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
CVE-2019-18363 1 Jetbrains 1 Teamcity 2024-08-05 5.3 Medium
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
CVE-2019-18369 1 Jetbrains 1 Youtrack 2024-08-05 5.3 Medium
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.