|
231
|
7.8 |
HIGH
Local
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
New
|
CWE-78
OS Command
|
CVE-2026-49366
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
8.0 |
HIGH
Network
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
New
|
CWE-862
Missing Authorization
|
CVE-2026-49367
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
8.7 |
HIGH
Network
|
-
|
-
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49368
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
4.3 |
MEDIUM
Network
|
-
|
-
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-49369
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
3.4 |
LOW
Network
|
-
|
-
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-49370
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
7.1 |
HIGH
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49371
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
7.5 |
HIGH
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-49372
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
7.1 |
HIGH
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
New
|
CWE-88
Argument Injection
|
CVE-2026-49373
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
7.6 |
HIGH
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
New
|
CWE-862
Missing Authorization
|
CVE-2026-49374
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
6.1 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1,
2025.11.5 reflected XSS was possible on the repository download page
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49375
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|