Latest CVE Feed
-
6.7
MEDIUMCVE-2021-31916
An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain acc... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31915
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31914
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.... Read more
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31913
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-31912
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31911
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31910
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31909
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31908
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-31907
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-31906
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31905
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.... Read more
Affected Products : youtrack- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31904
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.... Read more
Affected Products : teamcity- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31903
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.... Read more
Affected Products : youtrack- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31902
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.... Read more
Affected Products : youtrack- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31901
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.... Read more
Affected Products : hub- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-31900
In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.... Read more
Affected Products : code_with_me- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-31899
In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.... Read more
Affected Products : code_with_me- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31898
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.... Read more
Affected Products : webstorm- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31897
In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.... Read more
Affected Products : webstorm- Published: May. 11, 2021
- Modified: Nov. 21, 2024