JetBrains TeamCity, teamcity
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
The CVSS severity warrants an early asset and exposure review.In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
FIRST EPSS indicates an elevated probability of exploitation.In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
The CVSS severity warrants an early asset and exposure review.In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
The CVSS severity warrants an early asset and exposure review.In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
The CVSS severity warrants an early asset and exposure review.In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
The CVSS severity warrants an early asset and exposure review.In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
The CVSS severity warrants an early asset and exposure review.Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, including administrators. Settings/Team/RolePermission gated its write actions on the read-only view_users permission. Any user holding view_users could grant themselves or any other user arbitrary permissions, including manage_users and edit_order...
The CVSS severity warrants an early asset and exposure review.Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete, capture payment, archive, and start processing were callable with the read-only read_orders permission and did not require edit_orders. capturePayment could trigger an actual PSP capture (real funds movement). The order shipments table actions mark delivered and edit tracking were callable with...
The CVSS severity warrants an early asset and exposure review.SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng, which accepts attacker-controlled baseUrl and uses it directly to build outbound server-side fetches. An authenticated low-privilege user can point baseUrl at an internal or loopback HTTP service and receive the /search response body. This vulnerability is fixed in 1.18.0.
The CVSS severity warrants an early asset and exposure review.SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts extensionName: "." which bypasses sanitize-filename validation, causing the entire user extensions directory to be recursively deleted. No authentication is required in the default configuration. This vulnerability is fixed in 1.18.0.
The CVSS severity warrants an early asset and exposure review.SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to automatically log in users when SSO is configured. There is no validation that these headers originate from a trusted reverse proxy. Any network client that can reach the SillyTavern port directly can inject these headers and authenticate as any user, including administrators, without a password. Thi...
The CVSS severity warrants an early asset and exposure review.SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authentication, storing all session data (user handle, permissions) in a signed cookie. The endpoints POST /api/users/change-password and POST /api/users/recover-step2 only update the password hash in the database but do not expire current sessions. Because the session is stateless and stored entirely in the client cookie, there is no server-side mechani...
The CVSS severity warrants an early asset and exposure review.The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-42929 affects Danelec MacGregor Voyage Data Recorder (VDR) G4e, interschalt vdr g4e firmware, interschalt vdr g4e. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.