Total
275 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-65906 | 1 Jetbrains | 1 Teamcity | 2026-08-11 | N/A | 8.8 HIGH |
| In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | |||||
| CVE-2026-63077 | 1 Jetbrains | 1 Teamcity | 2026-08-06 | N/A | 9.8 CRITICAL |
| In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | |||||
| CVE-2026-49380 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 3.1 LOW |
| In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | |||||
| CVE-2026-49372 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 7.5 HIGH |
| In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | |||||
| CVE-2026-49373 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 7.1 HIGH |
| In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | |||||
| CVE-2026-49374 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 7.6 HIGH |
| In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | |||||
| CVE-2026-49376 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 6.5 MEDIUM |
| In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin | |||||
| CVE-2026-49375 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 6.1 MEDIUM |
| In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | |||||
| CVE-2026-49377 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 4.3 MEDIUM |
| In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | |||||
| CVE-2026-49381 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 3.4 LOW |
| In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | |||||
| CVE-2026-49378 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 4.3 MEDIUM |
| In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | |||||
| CVE-2026-49371 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 7.1 HIGH |
| In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | |||||
| CVE-2026-49379 | 1 Jetbrains | 1 Teamcity | 2026-07-22 | N/A | 6.5 MEDIUM |
| In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | |||||
| CVE-2026-59796 | 1 Jetbrains | 1 Teamcity | 2026-07-14 | N/A | 8.1 HIGH |
| In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | |||||
| CVE-2026-59793 | 1 Jetbrains | 1 Teamcity | 2026-07-14 | N/A | 8.8 HIGH |
| In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | |||||
| CVE-2026-59795 | 1 Jetbrains | 1 Teamcity | 2026-07-13 | N/A | 8.1 HIGH |
| In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | |||||
| CVE-2026-59794 | 1 Jetbrains | 1 Teamcity | 2026-07-10 | N/A | 7.3 HIGH |
| In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | |||||
| CVE-2026-44413 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 8.2 HIGH |
| In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access | |||||
| CVE-2026-28196 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 2.3 LOW |
| In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk | |||||
| CVE-2026-28195 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.3 MEDIUM |
| In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations | |||||
