Exposure of TeamCity

CI
55
exposure score
1
sites use
4
exploited
6
critical

CVEs

188 results
CVE-2024-24937MEDIUMIn JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possibleEPSS 0.4%CVE-2022-40979MEDIUMIn JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executableEPSS 0.4%CVE-2025-52878MEDIUMIn JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissionsEPSS 0.4%CVE-2023-34219MEDIUMIn JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration seEPSS 0.4%CVE-2026-49371HIGHIn JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possibleEPSS 0.4%CVE-2026-100255HIGHIn JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password resetEPSS 0.4%CVE-2026-59796HIGHIn JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checksEPSS 0.4%CVE-2023-34224MEDIUMIn JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possibleEPSS 0.3%CVE-2024-36375MEDIUMIn JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposedEPSS 0.3%CVE-2026-49379MEDIUMIn JetBrains TeamCity before 2026.1 credentials could be exposed in thread namesEPSS 0.3%CVE-2026-59795HIGHIn JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possibleEPSS 0.3%CVE-2024-28174MEDIUMIn JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperlyEPSS 0.3%CVE-2026-44413HIGHIn JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised accessEPSS 0.3%CVE-2024-36376MEDIUMIn JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissionsEPSS 0.3%CVE-2024-36377MEDIUMIn JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissionsEPSS 0.3%CVE-2024-36364MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisherEPSS 0.3%CVE-2024-41829LOWIn JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connectionEPSS 0.3%CVE-2024-43809LOWIn JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset pageEPSS 0.3%CVE-2026-59794HIGHIn JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported dataEPSS 0.3%CVE-2023-50870MEDIUMIn JetBrains TeamCity before 2023.11.1 a CSRF on login was possibleEPSS 0.3%