|
221861
|
9.8 |
CRITICAL
Network
|
ipswitch
|
moveit_transfer
|
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that …
|
CWE-89
SQL Injection
|
CVE-2019-18464
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221862
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-18369
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221863
|
7.3 |
HIGH
Network
|
jetbrains
|
toolbox
|
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
|
NVD-CWE-noinfo
|
CVE-2019-18368
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221864
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-18367
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221865
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-18366
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221866
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
|
NVD-CWE-noinfo CWE-269
Improper Privilege Management
|
CVE-2019-18365
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221867
|
9.8 |
CRITICAL
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-18364
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221868
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
|
NVD-CWE-noinfo
|
CVE-2019-18363
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221869
|
5.3 |
MEDIUM
Network
|
jetbrains
|
mps
|
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
|
NVD-CWE-noinfo
|
CVE-2019-18362
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221870
|
5.3 |
MEDIUM
Local
|
jetbrains
|
intellij_idea
|
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.
|
NVD-CWE-noinfo
|
CVE-2019-18361
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|