Jetbrains
Products
53- 277 CVEs
- 123 CVEs
- 70 CVEs
- 36 CVEs
- 21 CVEs
- 11 CVEs
- 11 CVEs
- 10 CVEs
- 9 CVEs
- 9 CVEs
- 8 CVEs
- 7 CVEs
- 6 CVEs
- 6 CVEs
- 6 CVEs
- 5 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- View all 53 products →
Recent CVEs
603| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27198 | Cri | 0.93 | 9.8 | 1.00 | KEV | Mar 4, 2024 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | |
| CVE-2023-42793 | Cri | 0.93 | 9.8 | 1.00 | KEV | Sep 19, 2023 | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | |
| CVE-2026-63077 | Cri | 0.76 | 9.8 | 0.11 | KEV | Jul 27, 2026 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | |
| CVE-2024-27199 | Hig | 0.73 | 7.3 | 1.00 | KEV | Mar 4, 2024 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | |
| CVE-2024-23917 | Cri | 0.68 | 9.8 | 0.54 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible | ||
| CVE-2019-15039 | Cri | 0.68 | 9.8 | 0.13 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. | ||
| CVE-2026-62422 | Cri | 0.65 | 10.0 | 0.00 | Jul 14, 2026 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | ||
| CVE-2026-50242 | Cri | 0.65 | 10.0 | 0.01 | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | ||
| CVE-2026-56142 | Cri | 0.64 | 9.9 | 0.01 | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible | ||
| CVE-2026-56141 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible | ||
| CVE-2022-25263 | Cri | 0.64 | 9.8 | 0.02 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration. | ||
| CVE-2022-25262 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains Hub before 2022.1.14434, SAML request takeover was possible. | ||
| CVE-2022-24442 | Cri | 0.64 | 9.8 | 0.04 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | ||
| CVE-2022-24340 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. | ||
| CVE-2022-24331 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. | ||
| CVE-2021-45977 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm… | ||
| CVE-2021-43202 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2021 | In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. | ||
| CVE-2021-43200 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient. | ||
| CVE-2021-43193 | Cri | 0.64 | 9.8 | 0.02 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. | ||
| CVE-2021-43185 | Cri | 0.64 | 9.8 | 0.02 | Nov 9, 2021 | JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. |
- risk 0.93cvss 9.8epss 1.00
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
- risk 0.93cvss 9.8epss 1.00
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
- risk 0.76cvss 9.8epss 0.11
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- risk 0.73cvss 7.3epss 1.00
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
- risk 0.68cvss 9.8epss 0.54
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
- risk 0.68cvss 9.8epss 0.13
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
- risk 0.65cvss 10.0epss 0.00
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
- risk 0.65cvss 10.0epss 0.01
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
- risk 0.64cvss 9.9epss 0.01
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
- risk 0.64cvss 9.8epss 0.01
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
- risk 0.64cvss 9.8epss 0.02
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
- risk 0.64cvss 9.8epss 0.01
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
- risk 0.64cvss 9.8epss 0.04
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
- risk 0.64cvss 9.8epss 0.01
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm…
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
- risk 0.64cvss 9.8epss 0.02
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
- risk 0.64cvss 9.8epss 0.02
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.