Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-68164 | Low | 0.18 | 2.7 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test | ||
| CVE-2025-68162 | Low | 0.18 | 2.7 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration | ||
| CVE-2025-67740 | Low | 0.18 | 2.7 | 0.00 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata | ||
| CVE-2025-64773 | Low | 0.18 | 2.7 | 0.00 | Nov 11, 2025 | In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit | ||
| CVE-2025-64682 | Low | 0.18 | 2.7 | 0.00 | Nov 10, 2025 | In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit | ||
| CVE-2025-64681 | Low | 0.18 | 2.7 | 0.00 | Nov 10, 2025 | In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations | ||
| CVE-2025-31141 | Low | 0.18 | 2.7 | 0.00 | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page | ||
| CVE-2024-24940 | Low | 0.18 | 2.8 | 0.00 | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives | ||
| CVE-2022-44622 | Low | 0.18 | 2.7 | 0.00 | Nov 3, 2022 | In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive | ||
| CVE-2022-29816 | Low | 0.18 | 2.8 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible | ||
| CVE-2021-31906 | Low | 0.18 | 2.7 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file. | ||
| CVE-2020-11692 | Low | 0.18 | 2.7 | 0.01 | Apr 22, 2020 | In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators. | ||
| CVE-2020-11686 | Low | 0.18 | 2.7 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings. | ||
| CVE-2024-41828 | Low | 0.17 | 2.6 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time | ||
| CVE-2021-25755 | Low | 0.16 | 2.5 | 0.00 | Feb 3, 2021 | In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the encrypted traffic. | ||
| CVE-2026-28196 | Low | 0.15 | 2.3 | 0.00 | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk | ||
| CVE-2022-29812 | Low | 0.15 | 2.3 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient | ||
| CVE-2022-44646 | Low | 0.14 | 2.2 | 0.00 | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings | ||
| CVE-2026-65908 | Hig | 0.00 | 8.6 | 0.00 | Jul 23, 2026 | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open | ||
| CVE-2026-65907 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | ||
| CVE-2026-64815 | Hig | 0.00 | 8.1 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | ||
| CVE-2026-64814 | Hig | 0.00 | 8.6 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | ||
| CVE-2026-64813 | Cri | 0.00 | 10.0 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | ||
| CVE-2026-64812 | Cri | 0.00 | 10.0 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | ||
| CVE-2026-64811 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | ||
| CVE-2026-64810 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | ||
| CVE-2026-64809 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter | ||
| CVE-2026-64808 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling | ||
| CVE-2026-64807 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration | ||
| CVE-2026-64806 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter | ||
| CVE-2026-64805 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling | ||
| CVE-2026-64804 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling | ||
| CVE-2026-64803 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK | ||
| CVE-2026-64802 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration | ||
| CVE-2026-64800 | Low | 0.00 | 3.5 | 0.00 | Jul 23, 2026 | In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default | ||
| CVE-2026-61492 | Low | 0.00 | 3.5 | 0.00 | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible | ||
| CVE-2026-59796 | Hig | 0.00 | 8.1 | 0.00 | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | ||
| CVE-2026-59795 | Hig | 0.00 | 8.1 | 0.00 | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | ||
| CVE-2026-59794 | Hig | 0.00 | 7.3 | 0.00 | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | ||
| CVE-2026-59793 | Hig | 0.00 | 8.8 | 0.00 | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | ||
| CVE-2026-59792 | Cri | 0.00 | 9.6 | 0.00 | Jul 10, 2026 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible | ||
| CVE-2026-59791 | Low | 0.00 | 3.5 | 0.00 | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | ||
| CVE-2026-57926 | Low | 0.00 | 2.6 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack | ||
| CVE-2026-57925 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags | ||
| CVE-2026-57924 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details | ||
| CVE-2026-57923 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings | ||
| CVE-2026-57922 | Low | 0.00 | 3.1 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible | ||
| CVE-2026-57921 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint | ||
| CVE-2022-29930 | Hig | 0.00 | 8.7 | 0.01 | May 12, 2022 | SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1. | ||
| CVE-2022-29035 | Low | 0.00 | 3.3 | 0.01 | Apr 11, 2022 | In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations |
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
- risk 0.18cvss 2.7epss 0.00
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
- risk 0.18cvss 2.7epss 0.00
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
- risk 0.18cvss 2.7epss 0.00
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
- risk 0.18cvss 2.8epss 0.00
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
- risk 0.18cvss 2.8epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
- risk 0.18cvss 2.7epss 0.01
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.
- risk 0.18cvss 2.7epss 0.01
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
- risk 0.18cvss 2.7epss 0.01
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
- risk 0.17cvss 2.6epss 0.00
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
- risk 0.16cvss 2.5epss 0.00
In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the encrypted traffic.
- risk 0.15cvss 2.3epss 0.00
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
- risk 0.15cvss 2.3epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
- risk 0.14cvss 2.2epss 0.00
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
- risk 0.00cvss 8.6epss 0.00
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
- risk 0.00cvss 9.1epss 0.00
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
- risk 0.00cvss 8.1epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
- risk 0.00cvss 8.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- risk 0.00cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
- risk 0.00cvss 4.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
- risk 0.00cvss 8.4epss 0.00
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
- risk 0.00cvss 8.4epss 0.00
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
- risk 0.00cvss 7.8epss 0.00
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
- risk 0.00cvss 8.4epss 0.00
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
- risk 0.00cvss 8.4epss 0.00
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
- risk 0.00cvss 8.4epss 0.00
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
- risk 0.00cvss 7.8epss 0.00
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
- risk 0.00cvss 7.8epss 0.00
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
- risk 0.00cvss 3.5epss 0.00
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
- risk 0.00cvss 3.5epss 0.00
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
- risk 0.00cvss 8.1epss 0.00
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
- risk 0.00cvss 8.1epss 0.00
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
- risk 0.00cvss 7.3epss 0.00
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
- risk 0.00cvss 8.8epss 0.00
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
- risk 0.00cvss 9.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
- risk 0.00cvss 3.5epss 0.00
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
- risk 0.00cvss 2.6epss 0.00
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
- risk 0.00cvss 5.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
- risk 0.00cvss 3.1epss 0.00
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
- risk 0.00cvss 8.7epss 0.01
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
- risk 0.00cvss 3.3epss 0.01
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
Page 12 of 13