Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15848 1 Jetbrains 1 Teamcity 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
CVE-2019-12841 1 Jetbrains 1 Teamcity 2024-02-04 5.0 MEDIUM 7.5 HIGH
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.
CVE-2019-12844 1 Jetbrains 1 Teamcity 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
CVE-2017-8316 1 Jetbrains 1 Intellij Idea 2024-02-04 7.8 HIGH 7.5 HIGH
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
CVE-2018-14878 1 Jetbrains 2 Dotpeek, Resharper Ultimate 2024-02-04 6.8 MEDIUM 7.8 HIGH
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.