Latest CVE Feed
-
5.3
MEDIUMCVE-2021-43194
In JetBrains TeamCity before 2021.1.2, user enumeration was possible.... Read more
Affected Products : teamcity- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43193
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.... Read more
Affected Products : teamcity- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-43192
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-43191
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-43190
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43189
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43188
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-43187
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-43186
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.... Read more
Affected Products : youtrack- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43185
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.... Read more
Affected Products : youtrack- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-43184
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.... Read more
Affected Products : youtrack- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43183
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.... Read more
Affected Products : hub- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43182
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.... Read more
Affected Products : hub- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-43181
In JetBrains Hub before 2021.1.13690, stored XSS is possible.... Read more
Affected Products : hub- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43180
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.... Read more
Affected Products : hub- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-43177
As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/... Read more
Affected Products : devise-two-factor- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-43176
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 takes a user-supplied “action” parameter and appends a .php file extension to locate and load the correct PHP file to implement the API call. Vulnerable versions of GOautodial do not sa... Read more
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43175
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOautodial validate t... Read more
- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43174
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-43173
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator h... Read more
- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024