|
241
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-49376
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
4.3 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
New
|
CWE-526
Cleartext Storage of Sensitive Information in an Environment Variable
|
CVE-2026-49377
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
4.3 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
New
|
CWE-862
Missing Authorization
|
CVE-2026-49378
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-49379
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
3.1 |
LOW
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
New
|
CWE-601
Open Redirect
|
CVE-2026-49380
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
3.4 |
LOW
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49381
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
4.5 |
MEDIUM
Local
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
New
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-49382
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
3.3 |
LOW
Local
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
New
|
CWE-611
XXE
|
CVE-2026-49383
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
6.1 |
MEDIUM
Network
|
-
|
-
|
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49384
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
New
|
CWE-862
Missing Authorization
|
CVE-2026-49385
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|