VYPR

Vendor CVEs

Jetbrains

All CVEs

650 total · sorted by risk
  • CVE-2022-29818LowApr 28, 2022
    risk 0.25cvss 3.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed

  • CVE-2022-29817LowApr 28, 2022
    risk 0.25cvss 3.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible

  • CVE-2021-25775LowFeb 3, 2021
    risk 0.25cvss 3.8epss 0.01

    In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

  • CVE-2026-86486LowSep 7, 2026
    risk 0.24cvss 3.7epss 0.00

    In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank

  • CVE-2025-54529LowJul 28, 2025
    risk 0.24cvss 3.7epss 0.00

    In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

  • CVE-2024-54155LowDec 4, 2024
    risk 0.24cvss 3.7epss 0.00

    In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

  • CVE-2024-43808LowAug 16, 2024
    risk 0.24cvss 3.7epss 0.00

    In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin

  • CVE-2022-38179MedAug 12, 2022
    risk 0.24cvss 4.7epss 0.00

    JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack

  • CVE-2022-29929LowMay 12, 2022
    risk 0.24cvss 3.7epss 0.00

    In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible

  • CVE-2026-86491LowSep 7, 2026
    risk 0.23cvss 3.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads

  • CVE-2026-75052LowAug 17, 2026
    risk 0.23cvss 3.6epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects

  • CVE-2025-68163LowDec 16, 2025
    risk 0.23cvss 3.5epss 0.00

    In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page

  • CVE-2024-54158LowDec 4, 2024
    risk 0.23cvss 3.5epss 0.00

    In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

  • CVE-2024-47951LowOct 8, 2024
    risk 0.23cvss 3.5epss 0.01

    In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

  • CVE-2024-47950LowOct 8, 2024
    risk 0.23cvss 3.5epss 0.01

    In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

  • CVE-2024-43809LowAug 16, 2024
    risk 0.23cvss 3.5epss 0.00

    In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page

  • CVE-2024-41829LowJul 22, 2024
    risk 0.23cvss 3.5epss 0.00

    In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

  • CVE-2024-41826LowJul 22, 2024
    risk 0.23cvss 3.5epss 0.00

    In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page

  • CVE-2024-38507LowJun 18, 2024
    risk 0.23cvss 3.5epss 0.00

    In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible

  • CVE-2024-35300LowMay 16, 2024
    risk 0.23cvss 3.5epss 0.00

    In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible

  • CVE-2023-43566LowSep 19, 2023
    risk 0.23cvss 3.5epss 0.01

    In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration

  • CVE-2023-41250LowAug 25, 2023
    risk 0.23cvss 3.5epss 0.00

    In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration

  • CVE-2022-45471LowNov 18, 2022
    risk 0.23cvss 3.5epss 0.01

    In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address

  • CVE-2022-37010LowJul 28, 2022
    risk 0.23cvss 3.6epss 0.00

    In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed

  • CVE-2022-34894LowJul 1, 2022
    risk 0.23cvss 3.5epss 0.01

    In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services

  • CVE-2026-49381LowMay 29, 2026
    risk 0.22cvss 3.4epss 0.00

    In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

  • CVE-2026-49370LowMay 29, 2026
    risk 0.22cvss 3.4epss 0.00

    In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

  • CVE-2026-86505LowSep 7, 2026
    risk 0.21cvss 3.3epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace

  • CVE-2026-86503LowSep 7, 2026
    risk 0.21cvss 3.3epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching

  • CVE-2026-86485LowSep 7, 2026
    risk 0.21cvss 3.3epss 0.00

    In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks

  • CVE-2026-49383LowMay 29, 2026
    risk 0.21cvss 3.3epss 0.00

    In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

  • CVE-2025-32054LowApr 3, 2025
    risk 0.21cvss 3.3epss 0.00

    In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file

  • CVE-2024-46970LowSep 16, 2024
    risk 0.21cvss 3.3epss 0.00

    In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible

  • CVE-2024-5899LowJun 18, 2024
    risk 0.21cvss 3.3epss 0.00

    When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls…

  • CVE-2024-24939LowFeb 6, 2024
    risk 0.21cvss 3.3epss 0.00

    In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

  • CVE-2023-38069LowJul 12, 2023
    risk 0.21cvss 3.3epss 0.00

    In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases

  • CVE-2023-34339LowJun 1, 2023
    risk 0.21cvss 3.3epss 0.00

    In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message

  • CVE-2022-48435LowApr 4, 2023
    risk 0.21cvss 3.3epss 0.00

    In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file

  • CVE-2022-38133LowAug 10, 2022
    risk 0.21cvss 3.2epss 0.00

    In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases

  • CVE-2021-26309LowMay 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.

  • CVE-2020-24366LowNov 16, 2020
    risk 0.21cvss 3.3epss 0.00

    Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

  • CVE-2026-86487LowSep 7, 2026
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

  • CVE-2026-49380LowMay 29, 2026
    risk 0.20cvss 3.1epss 0.00

    In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

  • CVE-2025-67739LowDec 11, 2025
    risk 0.20cvss 3.1epss 0.00

    In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

  • CVE-2024-54153LowDec 4, 2024
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

  • CVE-2022-29820LowApr 28, 2022
    risk 0.20cvss 3.0epss 0.00

    In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible

  • CVE-2026-86501LowSep 7, 2026
    risk 0.18cvss 2.8epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log

  • CVE-2025-68164LowDec 16, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test

  • CVE-2025-68162LowDec 16, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration

  • CVE-2025-67740LowDec 11, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata

Page 12 of 13