Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27198 | Cri | 0.93 | 9.8 | 1.00 | KEV | Mar 4, 2024 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | |
| CVE-2023-42793 | Cri | 0.93 | 9.8 | 1.00 | KEV | Sep 19, 2023 | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | |
| CVE-2026-63077 | Cri | 0.76 | 9.8 | 0.11 | KEV | Jul 27, 2026 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | |
| CVE-2024-27199 | Hig | 0.73 | 7.3 | 1.00 | KEV | Mar 4, 2024 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | |
| CVE-2024-23917 | Cri | 0.68 | 9.8 | 0.54 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible | ||
| CVE-2019-15039 | Cri | 0.68 | 9.8 | 0.13 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. | ||
| CVE-2026-62422 | Cri | 0.65 | 10.0 | 0.00 | Jul 14, 2026 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | ||
| CVE-2026-50242 | Cri | 0.65 | 10.0 | 0.01 | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | ||
| CVE-2026-56142 | Cri | 0.64 | 9.9 | 0.01 | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible | ||
| CVE-2026-56141 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible | ||
| CVE-2022-25263 | Cri | 0.64 | 9.8 | 0.02 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration. | ||
| CVE-2022-25262 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains Hub before 2022.1.14434, SAML request takeover was possible. | ||
| CVE-2022-24442 | Cri | 0.64 | 9.8 | 0.04 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | ||
| CVE-2022-24340 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. | ||
| CVE-2022-24331 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. | ||
| CVE-2021-45977 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm… | ||
| CVE-2021-43202 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2021 | In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. | ||
| CVE-2021-43200 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient. | ||
| CVE-2021-43193 | Cri | 0.64 | 9.8 | 0.02 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. | ||
| CVE-2021-43185 | Cri | 0.64 | 9.8 | 0.02 | Nov 9, 2021 | JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. | ||
| CVE-2021-43183 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. | ||
| CVE-2021-37544 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization. | ||
| CVE-2021-36209 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2021 | In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset. | ||
| CVE-2021-31915 | Cri | 0.64 | 9.8 | 0.03 | May 11, 2021 | In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. | ||
| CVE-2021-31914 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2021 | In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. | ||
| CVE-2021-31897 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2021 | In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects. | ||
| CVE-2021-31909 | Cri | 0.64 | 9.8 | 0.03 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible. | ||
| CVE-2021-25770 | Cri | 0.64 | 9.8 | 0.03 | Feb 3, 2021 | In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution. | ||
| CVE-2020-25207 | Cri | 0.64 | 9.8 | 0.05 | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler. | ||
| CVE-2020-11796 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2020 | In JetBrains Space through 2020-04-22, the password authentication implementation was insecure. | ||
| CVE-2020-11690 | Cri | 0.64 | 9.8 | 0.02 | Apr 22, 2020 | In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases. | ||
| CVE-2019-18364 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. | ||
| CVE-2019-12736 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2019 | JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection. | ||
| CVE-2019-12157 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2019 | In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands. | ||
| CVE-2019-12852 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168. | ||
| CVE-2019-9873 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8,… | ||
| CVE-2019-9823 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8,… | ||
| CVE-2019-9186 | Cri | 0.64 | 9.8 | 0.05 | Jul 3, 2019 | In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost… | ||
| CVE-2019-12867 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168. | ||
| CVE-2019-12866 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168. | ||
| CVE-2019-12850 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168. | ||
| CVE-2019-10104 | Cri | 0.64 | 9.8 | 0.04 | Jul 3, 2019 | In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all… | ||
| CVE-2019-10100 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the… | ||
| CVE-2024-37051 | Cri | 0.61 | 9.3 | 0.04 | Jun 10, 2024 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3,… | ||
| CVE-2026-25848 | Cri | 0.59 | 9.1 | 0.00 | Feb 9, 2026 | In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible | ||
| CVE-2023-34218 | Cri | 0.59 | 9.1 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible | ||
| CVE-2022-25260 | Cri | 0.59 | 9.1 | 0.02 | Feb 25, 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF). | ||
| CVE-2021-37549 | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient. | ||
| CVE-2026-65906 | Hig | 0.57 | 8.8 | 0.00 | Jul 23, 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | ||
| CVE-2026-49368 | Hig | 0.57 | 8.7 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible |
- risk 0.93cvss 9.8epss 1.00
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
- risk 0.93cvss 9.8epss 1.00
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
- risk 0.76cvss 9.8epss 0.11
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- risk 0.73cvss 7.3epss 1.00
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
- risk 0.68cvss 9.8epss 0.54
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
- risk 0.68cvss 9.8epss 0.13
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
- risk 0.65cvss 10.0epss 0.00
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
- risk 0.65cvss 10.0epss 0.01
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
- risk 0.64cvss 9.9epss 0.01
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
- risk 0.64cvss 9.8epss 0.01
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
- risk 0.64cvss 9.8epss 0.02
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
- risk 0.64cvss 9.8epss 0.01
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
- risk 0.64cvss 9.8epss 0.04
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
- risk 0.64cvss 9.8epss 0.01
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm…
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
- risk 0.64cvss 9.8epss 0.02
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
- risk 0.64cvss 9.8epss 0.02
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
- risk 0.64cvss 9.8epss 0.01
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
- risk 0.64cvss 9.8epss 0.01
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
- risk 0.64cvss 9.8epss 0.03
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.
- risk 0.64cvss 9.8epss 0.02
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.
- risk 0.64cvss 9.8epss 0.02
In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.
- risk 0.64cvss 9.8epss 0.03
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
- risk 0.64cvss 9.8epss 0.03
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
- risk 0.64cvss 9.8epss 0.05
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
- risk 0.64cvss 9.8epss 0.01
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
- risk 0.64cvss 9.8epss 0.02
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
- risk 0.64cvss 9.8epss 0.03
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
- risk 0.64cvss 9.8epss 0.02
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
- risk 0.64cvss 9.8epss 0.02
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
- risk 0.64cvss 9.8epss 0.02
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
- risk 0.64cvss 9.8epss 0.02
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8,…
- risk 0.64cvss 9.8epss 0.02
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8,…
- risk 0.64cvss 9.8epss 0.05
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost…
- risk 0.64cvss 9.8epss 0.02
Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
- risk 0.64cvss 9.8epss 0.02
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
- risk 0.64cvss 9.8epss 0.02
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.
- risk 0.64cvss 9.8epss 0.04
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all…
- risk 0.64cvss 9.8epss 0.02
In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the…
- risk 0.61cvss 9.3epss 0.04
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3,…
- risk 0.59cvss 9.1epss 0.00
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
- risk 0.59cvss 9.1epss 0.01
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
- risk 0.59cvss 9.1epss 0.02
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
- risk 0.59cvss 9.1epss 0.01
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
- risk 0.57cvss 8.8epss 0.00
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
- risk 0.57cvss 8.7epss 0.00
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
Page 1 of 13