Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29818 | Low | 0.25 | 3.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed | ||
| CVE-2022-29817 | Low | 0.25 | 3.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible | ||
| CVE-2021-25775 | Low | 0.25 | 3.8 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. | ||
| CVE-2026-86486 | Low | 0.24 | 3.7 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | ||
| CVE-2025-54529 | Low | 0.24 | 3.7 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration | ||
| CVE-2024-54155 | Low | 0.24 | 3.7 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | ||
| CVE-2024-43808 | Low | 0.24 | 3.7 | 0.00 | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin | ||
| CVE-2022-38179 | Med | 0.24 | 4.7 | 0.00 | Aug 12, 2022 | JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack | ||
| CVE-2022-29929 | Low | 0.24 | 3.7 | 0.00 | May 12, 2022 | In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible | ||
| CVE-2026-86491 | Low | 0.23 | 3.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | ||
| CVE-2026-75052 | Low | 0.23 | 3.6 | 0.00 | Aug 17, 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects | ||
| CVE-2025-68163 | Low | 0.23 | 3.5 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page | ||
| CVE-2024-54158 | Low | 0.23 | 3.5 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | ||
| CVE-2024-47951 | Low | 0.23 | 3.5 | 0.01 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings | ||
| CVE-2024-47950 | Low | 0.23 | 3.5 | 0.01 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings | ||
| CVE-2024-43809 | Low | 0.23 | 3.5 | 0.00 | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page | ||
| CVE-2024-41829 | Low | 0.23 | 3.5 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection | ||
| CVE-2024-41826 | Low | 0.23 | 3.5 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page | ||
| CVE-2024-38507 | Low | 0.23 | 3.5 | 0.00 | Jun 18, 2024 | In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible | ||
| CVE-2024-35300 | Low | 0.23 | 3.5 | 0.00 | May 16, 2024 | In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible | ||
| CVE-2023-43566 | Low | 0.23 | 3.5 | 0.01 | Sep 19, 2023 | In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration | ||
| CVE-2023-41250 | Low | 0.23 | 3.5 | 0.00 | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration | ||
| CVE-2022-45471 | Low | 0.23 | 3.5 | 0.01 | Nov 18, 2022 | In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address | ||
| CVE-2022-37010 | Low | 0.23 | 3.6 | 0.00 | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed | ||
| CVE-2022-34894 | Low | 0.23 | 3.5 | 0.01 | Jul 1, 2022 | In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services | ||
| CVE-2026-49381 | Low | 0.22 | 3.4 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | ||
| CVE-2026-49370 | Low | 0.22 | 3.4 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests | ||
| CVE-2026-86505 | Low | 0.21 | 3.3 | 0.00 | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace | ||
| CVE-2026-86503 | Low | 0.21 | 3.3 | 0.00 | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching | ||
| CVE-2026-86485 | Low | 0.21 | 3.3 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | ||
| CVE-2026-49383 | Low | 0.21 | 3.3 | 0.00 | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible | ||
| CVE-2025-32054 | Low | 0.21 | 3.3 | 0.00 | Apr 3, 2025 | In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file | ||
| CVE-2024-46970 | Low | 0.21 | 3.3 | 0.00 | Sep 16, 2024 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible | ||
| CVE-2024-5899 | Low | 0.21 | 3.3 | 0.00 | Jun 18, 2024 | When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls… | ||
| CVE-2024-24939 | Low | 0.21 | 3.3 | 0.00 | Feb 6, 2024 | In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible | ||
| CVE-2023-38069 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2023 | In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases | ||
| CVE-2023-34339 | Low | 0.21 | 3.3 | 0.00 | Jun 1, 2023 | In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message | ||
| CVE-2022-48435 | Low | 0.21 | 3.3 | 0.00 | Apr 4, 2023 | In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file | ||
| CVE-2022-38133 | Low | 0.21 | 3.2 | 0.00 | Aug 10, 2022 | In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases | ||
| CVE-2021-26309 | Low | 0.21 | 3.3 | 0.00 | May 11, 2021 | Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions. | ||
| CVE-2020-24366 | Low | 0.21 | 3.3 | 0.00 | Nov 16, 2020 | Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups. | ||
| CVE-2026-86487 | Low | 0.20 | 3.1 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | ||
| CVE-2026-49380 | Low | 0.20 | 3.1 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | ||
| CVE-2025-67739 | Low | 0.20 | 3.1 | 0.00 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure | ||
| CVE-2024-54153 | Low | 0.20 | 3.1 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | ||
| CVE-2022-29820 | Low | 0.20 | 3.0 | 0.00 | Apr 28, 2022 | In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible | ||
| CVE-2026-86501 | Low | 0.18 | 2.8 | 0.00 | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log | ||
| CVE-2025-68164 | Low | 0.18 | 2.7 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test | ||
| CVE-2025-68162 | Low | 0.18 | 2.7 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration | ||
| CVE-2025-67740 | Low | 0.18 | 2.7 | 0.00 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata |
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
- risk 0.25cvss 3.8epss 0.01
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
- risk 0.24cvss 3.7epss 0.00
In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
- risk 0.24cvss 3.7epss 0.00
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
- risk 0.24cvss 4.7epss 0.00
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
- risk 0.23cvss 3.5epss 0.00
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
- risk 0.23cvss 3.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
- risk 0.23cvss 3.5epss 0.00
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
- risk 0.23cvss 3.5epss 0.00
In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
- risk 0.23cvss 3.5epss 0.01
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
- risk 0.23cvss 3.6epss 0.00
In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed
- risk 0.23cvss 3.5epss 0.01
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
- risk 0.22cvss 3.4epss 0.00
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
- risk 0.22cvss 3.4epss 0.00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching
- risk 0.21cvss 3.3epss 0.00
In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
- risk 0.21cvss 3.3epss 0.00
When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls…
- risk 0.21cvss 3.3epss 0.00
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
- risk 0.21cvss 3.3epss 0.00
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
- risk 0.21cvss 3.3epss 0.00
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
- risk 0.21cvss 3.2epss 0.00
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
- risk 0.21cvss 3.3epss 0.00
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
- risk 0.21cvss 3.3epss 0.00
Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.
- risk 0.20cvss 3.1epss 0.00
In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content
- risk 0.20cvss 3.1epss 0.00
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
- risk 0.20cvss 3.1epss 0.00
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
- risk 0.20cvss 3.1epss 0.00
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
- risk 0.20cvss 3.0epss 0.00
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
- risk 0.18cvss 2.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
Page 12 of 13