Intellij Idea
by Jetbrains
CVEs (70)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-24940 | Low | 0.18 | 2.8 | 0.00 | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives | ||
| CVE-2022-29816 | Low | 0.18 | 2.8 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible | ||
| CVE-2022-29812 | Low | 0.15 | 2.3 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient | ||
| CVE-2026-64815 | Hig | 0.00 | 8.1 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | ||
| CVE-2026-64814 | Hig | 0.00 | 8.6 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | ||
| CVE-2026-64813 | Cri | 0.00 | 10.0 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | ||
| CVE-2026-64812 | Cri | 0.00 | 10.0 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | ||
| CVE-2026-64811 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | ||
| CVE-2026-64810 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | ||
| CVE-2026-59792 | Cri | 0.00 | 9.6 | 0.00 | Jul 10, 2026 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible |
- risk 0.18cvss 2.8epss 0.00
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
- risk 0.18cvss 2.8epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
- risk 0.15cvss 2.3epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
- risk 0.00cvss 8.1epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
- risk 0.00cvss 8.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- risk 0.00cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
- risk 0.00cvss 4.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
- risk 0.00cvss 9.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
Page 4 of 4