Export limit exceeded: 357918 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (357918 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-43197 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 6.1 Medium |
| In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS. | ||||
| CVE-2021-43196 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 7.5 High |
| In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. | ||||
| CVE-2021-43195 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 5.3 Medium |
| In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing. | ||||
| CVE-2021-43194 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 5.3 Medium |
| In JetBrains TeamCity before 2021.1.2, user enumeration was possible. | ||||
| CVE-2021-43193 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 9.8 Critical |
| In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. | ||||
| CVE-2021-43192 | 2 Apple, Jetbrains | 2 Iphone Os, Youtrack Mobile | 2024-11-21 | 5.3 Medium |
| In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. | ||||
| CVE-2021-43191 | 3 Apple, Google, Jetbrains | 3 Iphone Os, Android, Youtrack Mobile | 2024-11-21 | 5.3 Medium |
| JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. | ||||
| CVE-2021-43190 | 2 Google, Jetbrains | 2 Android, Youtrack Mobile | 2024-11-21 | 5.3 Medium |
| In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. | ||||
| CVE-2021-43189 | 2 Google, Jetbrains | 2 Android, Youtrack Mobile | 2024-11-21 | 7.3 High |
| In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. | ||||
| CVE-2021-43188 | 2 Apple, Jetbrains | 2 Iphone Os, Youtrack Mobile | 2024-11-21 | 7.3 High |
| In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. | ||||
| CVE-2021-43187 | 2 Apple, Jetbrains | 2 Iphone Os, Youtrack Mobile | 2024-11-21 | 5.3 Medium |
| In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. | ||||
| CVE-2021-43186 | 1 Jetbrains | 1 Youtrack | 2024-11-21 | 5.4 Medium |
| JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. | ||||
| CVE-2021-43185 | 1 Jetbrains | 1 Youtrack | 2024-11-21 | 9.8 Critical |
| JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. | ||||
| CVE-2021-43184 | 1 Jetbrains | 1 Youtrack | 2024-11-21 | 5.4 Medium |
| In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. | ||||
| CVE-2021-43183 | 1 Jetbrains | 1 Hub | 2024-11-21 | 9.8 Critical |
| In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. | ||||
| CVE-2021-43182 | 1 Jetbrains | 1 Hub | 2024-11-21 | 7.5 High |
| In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. | ||||
| CVE-2021-43181 | 1 Jetbrains | 1 Hub | 2024-11-21 | 6.1 Medium |
| In JetBrains Hub before 2021.1.13690, stored XSS is possible. | ||||
| CVE-2021-43180 | 1 Jetbrains | 1 Hub | 2024-11-21 | 7.5 High |
| In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. | ||||
| CVE-2021-43177 | 1 Tinfoilsecurity | 1 Devise-two-factor | 2024-11-21 | 5.3 Medium |
| As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N) | ||||
| CVE-2021-43176 | 1 Goautodial | 2 Goautodial, Goautodial Api | 2024-11-21 | 8.8 High |
| The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 takes a user-supplied “action” parameter and appends a .php file extension to locate and load the correct PHP file to implement the API call. Vulnerable versions of GOautodial do not sanitize the user input that specifies the action. This permits an attacker to execute any PHP source file with a .php extension that is present on the disk and readable by the GOautodial web server process. Combined with CVE-2021-43175, it is possible for the attacker to do this without valid credentials. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C | ||||