|
411
|
6.5 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-49376
|
2026-06-2 21:39 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
412
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
Update
|
CWE-526
Cleartext Storage of Sensitive Information in an Environment Variable
|
CVE-2026-49377
|
2026-06-2 21:38 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
413
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
Update
|
CWE-862
Missing Authorization
|
CVE-2026-49378
|
2026-06-2 21:38 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
414
|
6.5 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
Update
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-49379
|
2026-06-2 21:37 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
415
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
Update
|
CWE-601
Open Redirect
|
CVE-2026-49380
|
2026-06-2 21:37 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
416
|
4.8 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-49381
|
2026-06-2 21:36 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
417
|
5.5 |
MEDIUM
Local
|
synology
|
storage_manager
|
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive inf…
Update
|
CWE-598
Information Exposure Through Query Strings in GET Request
|
CVE-2026-2237
|
2026-06-2 19:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
418
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-49372
|
2026-06-2 13:07 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
419
|
8.2 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-49371
|
2026-06-2 13:06 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
420
|
7.5 |
HIGH
Network
|
-
|
-
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifyin…
Update
|
CWE-290 CWE-345
Authentication Bypass by Spoofing Insufficient Verification of Data Authenticity
|
CVE-2026-47123
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|