Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 358 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-43187 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
CVE-2021-43185 1 Jetbrains 1 Youtrack 2023-12-10 7.5 HIGH 9.8 CRITICAL
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
CVE-2021-43193 1 Jetbrains 1 Teamcity 2023-12-10 7.5 HIGH 9.8 CRITICAL
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
CVE-2021-43191 3 Apple, Google, Jetbrains 3 Iphone Os, Android, Youtrack Mobile 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
CVE-2021-43181 1 Jetbrains 1 Hub 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
CVE-2021-43186 1 Jetbrains 1 Youtrack 2023-12-10 3.5 LOW 5.4 MEDIUM
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
CVE-2021-43182 1 Jetbrains 1 Hub 2023-12-10 5.0 MEDIUM 7.5 HIGH
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
CVE-2021-31903 1 Jetbrains 1 Youtrack 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
CVE-2021-37548 1 Jetbrains 1 Teamcity 2023-12-10 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
CVE-2021-31905 1 Jetbrains 1 Youtrack 2023-12-10 5.0 MEDIUM 7.5 HIGH
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
CVE-2021-31898 1 Jetbrains 1 Webstorm 2023-12-10 5.0 MEDIUM 7.5 HIGH
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
CVE-2021-27733 1 Jetbrains 1 Youtrack 2023-12-10 3.5 LOW 5.4 MEDIUM
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
CVE-2021-37554 1 Jetbrains 1 Youtrack 2023-12-10 4.0 MEDIUM 4.3 MEDIUM
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
CVE-2021-3315 1 Jetbrains 1 Teamcity 2023-12-10 3.5 LOW 5.4 MEDIUM
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
CVE-2021-31914 2 Jetbrains, Microsoft 2 Teamcity, Windows 2023-12-10 7.5 HIGH 9.8 CRITICAL
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.
CVE-2021-31900 1 Jetbrains 1 Code With Me 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.
CVE-2021-31897 1 Jetbrains 1 Webstorm 2023-12-10 7.5 HIGH 9.8 CRITICAL
In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.
CVE-2021-31901 1 Jetbrains 1 Hub 2023-12-10 5.0 MEDIUM 7.5 HIGH
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
CVE-2021-31908 1 Jetbrains 1 Teamcity 2023-12-10 3.5 LOW 5.4 MEDIUM
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
CVE-2021-31910 1 Jetbrains 1 Teamcity 2023-12-10 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.