5.8
CVE-2025-54535 -
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
4.8
CVE-2025-54534 -
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
4.3
CVE-2025-54533 -
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
4.3
CVE-2025-54532 -
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
7.7
CVE-2025-54531 -
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
7.5
CVE-2025-54530 -
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
3.7
CVE-2025-54529 -
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
5.4
CVE-2025-54528 -
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
6.1
CVE-2025-54527 -
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
7.1
CVE-2025-6250 - Privilege Management for Windows - Elevation of Privilege
Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.