Search Results (692 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100279 1 Jetbrains 1 Youtrack 2026-10-02 6.5 Medium
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
CVE-2026-100280 1 Jetbrains 1 Youtrack 2026-10-02 3.1 Low
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVE-2026-100275 1 Jetbrains 1 Youtrack 2026-10-02 6.9 Medium
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVE-2026-103493 1 Jetbrains 1 Youtrack 2026-10-01 8.1 High
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVE-2026-100269 1 Jetbrains 1 Youtrack 2026-10-01 4.3 Medium
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
CVE-2026-100268 1 Jetbrains 1 Youtrack 2026-10-01 7.7 High
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVE-2026-100267 1 Jetbrains 1 Youtrack 2026-10-01 5.9 Medium
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVE-2026-103489 1 Jetbrains 1 Youtrack 2026-10-01 2 Low
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
CVE-2026-103491 1 Jetbrains 1 Youtrack 2026-10-01 6.5 Medium
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVE-2026-103497 1 Jetbrains 1 Youtrack 2026-10-01 5.5 Medium
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVE-2026-103496 1 Jetbrains 1 Youtrack 2026-10-01 5.4 Medium
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVE-2026-103495 1 Jetbrains 1 Youtrack 2026-10-01 4.3 Medium
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVE-2026-103494 1 Jetbrains 1 Youtrack 2026-10-01 6.6 Medium
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVE-2026-103492 1 Jetbrains 1 Youtrack 2026-10-01 6.5 Medium
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVE-2026-103490 1 Jetbrains 1 Youtrack 2026-10-01 7.2 High
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
CVE-2026-103488 1 Jetbrains 1 Youtrack 2026-10-01 7.1 High
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
CVE-2026-100254 1 Jetbrains 1 Teamcity 2026-10-01 8.8 High
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
CVE-2026-100253 1 Jetbrains 1 Teamcity 2026-10-01 8.8 High
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL
CVE-2026-63077 1 Jetbrains 1 Teamcity 2026-09-28 9.8 Critical
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVE-2026-49373 1 Jetbrains 1 Teamcity 2026-09-24 7.1 High
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings