Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-36374 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible | ||
| CVE-2024-36373 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible | ||
| CVE-2024-36372 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible | ||
| CVE-2024-36371 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible | ||
| CVE-2024-36370 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible | ||
| CVE-2024-36369 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible | ||
| CVE-2024-36368 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible | ||
| CVE-2024-36367 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible | ||
| CVE-2024-36363 | Med | 0.30 | 4.6 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible | ||
| CVE-2024-24937 | Med | 0.30 | 4.6 | 0.00 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible | ||
| CVE-2024-22370 | Med | 0.30 | 4.6 | 0.00 | Jan 9, 2024 | In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible | ||
| CVE-2023-41248 | Med | 0.30 | 4.6 | 0.00 | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration | ||
| CVE-2023-39175 | Med | 0.30 | 4.6 | 0.01 | Jul 25, 2023 | In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible | ||
| CVE-2023-38066 | Med | 0.30 | 4.6 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads | ||
| CVE-2023-38065 | Med | 0.30 | 4.6 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible | ||
| CVE-2023-38063 | Med | 0.30 | 4.6 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible | ||
| CVE-2023-38061 | Med | 0.30 | 4.6 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible | ||
| CVE-2023-35054 | Med | 0.30 | 4.6 | 0.01 | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible | ||
| CVE-2023-34229 | Med | 0.30 | 4.6 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible | ||
| CVE-2023-34226 | Med | 0.30 | 4.6 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible | ||
| CVE-2023-34222 | Med | 0.30 | 4.6 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible | ||
| CVE-2023-34221 | Med | 0.30 | 4.6 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible | ||
| CVE-2022-48427 | Med | 0.30 | 4.6 | 0.01 | Mar 27, 2023 | In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible | ||
| CVE-2022-48429 | Med | 0.30 | 4.6 | 0.01 | Mar 27, 2023 | In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible | ||
| CVE-2022-48426 | Med | 0.30 | 4.6 | 0.01 | Mar 27, 2023 | In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible | ||
| CVE-2022-29927 | Med | 0.30 | 4.6 | 0.02 | May 12, 2022 | In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible | ||
| CVE-2022-28649 | Med | 0.30 | 4.6 | 0.00 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description | ||
| CVE-2026-75059 | Med | 0.29 | 4.4 | 0.00 | Aug 17, 2026 | In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible | ||
| CVE-2026-49382 | Med | 0.29 | 4.5 | 0.00 | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin | ||
| CVE-2022-48431 | Med | 0.29 | 4.5 | 0.00 | Mar 29, 2023 | In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation. | ||
| CVE-2022-40979 | Med | 0.29 | 4.4 | 0.00 | Sep 23, 2022 | In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable | ||
| CVE-2022-29928 | Med | 0.29 | 4.4 | 0.00 | May 12, 2022 | In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible | ||
| CVE-2026-86499 | Med | 0.28 | 4.3 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission | ||
| CVE-2026-86496 | Med | 0.28 | 4.3 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses | ||
| CVE-2026-86481 | Med | 0.28 | 4.3 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | ||
| CVE-2026-75046 | Med | 0.28 | 4.3 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | ||
| CVE-2026-49378 | Med | 0.28 | 4.3 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | ||
| CVE-2026-49377 | Med | 0.28 | 4.3 | 0.01 | May 29, 2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | ||
| CVE-2026-49369 | Med | 0.28 | 4.3 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages | ||
| CVE-2026-28195 | Med | 0.28 | 4.3 | 0.00 | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations | ||
| CVE-2026-28194 | Med | 0.28 | 4.3 | 0.00 | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow | ||
| CVE-2025-64684 | Med | 0.28 | 4.3 | 0.00 | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form | ||
| CVE-2025-57734 | Med | 0.28 | 4.3 | 0.01 | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files | ||
| CVE-2025-54533 | Med | 0.28 | 4.3 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration | ||
| CVE-2025-54532 | Med | 0.28 | 4.3 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies | ||
| CVE-2025-52878 | Med | 0.28 | 4.3 | 0.00 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions | ||
| CVE-2025-47854 | Med | 0.28 | 4.3 | 0.00 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page | ||
| CVE-2025-47850 | Med | 0.28 | 4.3 | 0.00 | May 20, 2025 | In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning | ||
| CVE-2025-46432 | Med | 0.28 | 4.3 | 0.01 | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs | ||
| CVE-2025-31139 | Med | 0.28 | 4.3 | 0.01 | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log |
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
- risk 0.30cvss 4.6epss 0.02
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
- risk 0.29cvss 4.4epss 0.00
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
- risk 0.29cvss 4.5epss 0.00
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
- risk 0.29cvss 4.5epss 0.00
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
- risk 0.29cvss 4.4epss 0.00
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
- risk 0.29cvss 4.4epss 0.00
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
Page 10 of 13