CVE-2025-68165
- EPSS 4.15%
- Veröffentlicht 16.12.2025 15:27:29
- Zuletzt bearbeitet 18.12.2025 19:20:59
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
CVE-2025-68164
- EPSS 0.24%
- Veröffentlicht 16.12.2025 15:27:28
- Zuletzt bearbeitet 18.12.2025 19:22:25
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
CVE-2025-68162
- EPSS 0.21%
- Veröffentlicht 16.12.2025 15:27:27
- Zuletzt bearbeitet 18.12.2025 19:24:08
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
CVE-2025-68163
- EPSS 0.19%
- Veröffentlicht 16.12.2025 15:27:27
- Zuletzt bearbeitet 18.12.2025 19:23:12
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
CVE-2025-67742
- EPSS 0.79%
- Veröffentlicht 11.12.2025 15:19:07
- Zuletzt bearbeitet 07.10.2026 20:10:01
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
CVE-2025-67741
- EPSS 0.49%
- Veröffentlicht 11.12.2025 15:19:06
- Zuletzt bearbeitet 07.10.2026 20:10:01
In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
CVE-2025-67739
- EPSS 0.16%
- Veröffentlicht 11.12.2025 15:19:05
- Zuletzt bearbeitet 07.10.2026 20:10:01
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
CVE-2025-67740
- EPSS 0.22%
- Veröffentlicht 11.12.2025 15:19:05
- Zuletzt bearbeitet 07.10.2026 20:10:01
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
CVE-2025-59457
- EPSS 0.81%
- Veröffentlicht 17.09.2025 09:15:32
- Zuletzt bearbeitet 22.09.2025 17:07:35
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
CVE-2025-59455
- EPSS 0.41%
- Veröffentlicht 17.09.2025 09:15:31
- Zuletzt bearbeitet 22.09.2025 17:07:40
In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition