Medium
CVSS: 6.8
In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled
Critical
CVSS: 9.1
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Medium
CVSS: 6.5
Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.
Critical
CVSS: 9.8
An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
Medium
CVSS: 5.3
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
Low
CVSS: 2.7
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
Low
CVSS: 2.7
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
Medium
CVSS: 6.7
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping