VYPR

Intellij Idea

by Jetbrains

CVEs (82)

  • CVE-2021-30006HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

  • CVE-2020-7914HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.

  • CVE-2020-7905HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.

  • CVE-2017-8316HigAug 3, 2018
    risk 0.49cvss 7.5epss 0.02

    IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.

  • CVE-2026-41882HigApr 30, 2026
    risk 0.48cvss 7.4epss 0.00

    In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

  • CVE-2020-7904HigJan 30, 2020
    risk 0.48cvss 7.4epss 0.01

    In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

  • CVE-2019-10103HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.

  • CVE-2022-29819MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible

  • CVE-2022-29815MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible

  • CVE-2022-29814MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible

  • CVE-2022-29813MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible

  • CVE-2025-57729MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

  • CVE-2025-57728MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

  • CVE-2026-75054MedAug 17, 2026
    risk 0.41cvss 6.3epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

  • CVE-2023-51655MedDec 21, 2023
    risk 0.41cvss 6.3epss 0.00

    In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration

  • CVE-2026-75057MedAug 17, 2026
    risk 0.40cvss 6.2epss 0.00

    In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

  • CVE-2024-24941MedFeb 6, 2024
    risk 0.40cvss 6.1epss 0.00

    In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

  • CVE-2022-48433MedMar 29, 2023
    risk 0.40cvss 6.1epss 0.01

    In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.

  • CVE-2022-46826MedDec 8, 2022
    risk 0.40cvss 6.2epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.

  • CVE-2019-14954MedOct 1, 2019
    risk 0.38cvss 5.9epss 0.01

    JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.

Page 2 of 5