Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2021-31913

    In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-31912

    In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-31911

    In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31910

    In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-31909

    In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-31908

    In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-31907

    In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 4.0

    MEDIUM
    CVE-2021-31906

    In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31905

    In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.... Read more

    Affected Products : youtrack
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-31904

    In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.... Read more

    Affected Products : teamcity
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-31903

    In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.... Read more

    Affected Products : youtrack
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31902

    In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.... Read more

    Affected Products : youtrack
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31901

    In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.... Read more

    Affected Products : hub
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-31900

    In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.... Read more

    Affected Products : code_with_me
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-31899

    In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.... Read more

    Affected Products : code_with_me
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-31898

    In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.... Read more

    Affected Products : webstorm
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-31897

    In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.... Read more

    Affected Products : webstorm
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-31894

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM v... Read more

    • Published: Jul. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-31893

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 O... Read more

    • Published: Jul. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2021-31892

    A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), S... Read more

    • Published: Jul. 13, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 293308 Results