5.8

CVSS3.1

CVE-2025-54535 -

In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 4:30 p.m.

4.8

CVSS3.1

CVE-2025-54534 -

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 4:30 p.m.

4.3

CVSS3.1

CVE-2025-54533 -

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 4:30 p.m.

4.3

CVSS3.1

CVE-2025-54532 -

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 4:31 p.m.

7.7

CVSS3.1

CVE-2025-54531 -

In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.1

CVE-2025-54530 -

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

3.7

CVSS3.1

CVE-2025-54529 -

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 7:50 p.m.

5.4

CVSS3.1

CVE-2025-54528 -

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 7:50 p.m.

6.1

CVSS3.1

CVE-2025-54527 -

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

๐Ÿ“… Published: July 28, 2025, 4:20 p.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 7:23 p.m.

7.1

CVSS4.0

CVE-2025-6250 - Privilege Management for Windows - Elevation of Privilege

Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.

๐Ÿ“… Published: July 28, 2025, 3:40 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 1:45 p.m.
Total resulsts: 349182
Page 4485 of 34,919
ยซ previous page ยป next page
Filters