CVE-2026-49373
- EPSS 13.03%
- Veröffentlicht 29.05.2026 18:15:48
- Zuletzt bearbeitet 22.07.2026 06:10:00
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
CVE-2026-49374
- EPSS 0.23%
- Veröffentlicht 29.05.2026 18:15:48
- Zuletzt bearbeitet 22.07.2026 06:10:00
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
CVE-2026-49371
- EPSS 0.26%
- Veröffentlicht 29.05.2026 18:15:47
- Zuletzt bearbeitet 22.07.2026 06:10:00
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-44413
- EPSS 0.27%
- Veröffentlicht 11.05.2026 18:16:38
- Zuletzt bearbeitet 12.05.2026 19:59:34
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-28196
- EPSS 0.13%
- Veröffentlicht 25.02.2026 12:57:29
- Zuletzt bearbeitet 25.02.2026 17:17:14
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
CVE-2026-28194
- EPSS 0.16%
- Veröffentlicht 25.02.2026 12:57:28
- Zuletzt bearbeitet 25.02.2026 17:16:54
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
CVE-2026-28195
- EPSS 0.16%
- Veröffentlicht 25.02.2026 12:57:28
- Zuletzt bearbeitet 25.02.2026 17:17:05
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
CVE-2025-68268
- EPSS 0.2%
- Veröffentlicht 16.12.2025 15:27:31
- Zuletzt bearbeitet 18.12.2025 19:11:57
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
CVE-2025-68166
- EPSS 0.2%
- Veröffentlicht 16.12.2025 15:27:30
- Zuletzt bearbeitet 18.12.2025 19:20:38
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
CVE-2025-68267
- EPSS 0.21%
- Veröffentlicht 16.12.2025 15:27:30
- Zuletzt bearbeitet 18.12.2025 19:20:12
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token