9.6
CVE-2025-64689 -
In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token
7.4
CVE-2025-64688 -
In JetBrains YouTrack before 2025.3.104432 missing VCS URL validation allowed delegation to unauthorized repositories from the Junie widget
5.4
CVE-2025-64687 -
In JetBrains YouTrack before 2025.3.104432 improper access control allowed modify MCP tool logic
3.1
CVE-2025-64686 -
In JetBrains YouTrack before 2025.3.104432 missing user principal cleanup led to reuse of incorrect authorization context
8.1
CVE-2025-64685 -
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
4.5
CVE-2025-64684 -
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
5.3
CVE-2025-64683 -
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
2.7
CVE-2025-64682 -
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
2.7
CVE-2025-64681 -
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
5.3
CVE-2025-12939 - SourceCodester Interview Management System addCandidate.php sql injection
A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched remotely. The exploit has bโฆ