VYPR

Vendor CVEs

Jetbrains

All CVEs

650 total · sorted by risk
  • CVE-2021-37549CriAug 6, 2021
    risk 0.59cvss 9.1epss 0.01

    In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

  • CVE-2026-86482HigSep 7, 2026
    risk 0.57cvss 8.8epss 0.00

    In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation

  • CVE-2026-65906HigJul 23, 2026
    risk 0.57cvss 8.8epss 0.01

    In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

  • CVE-2026-49368HigMay 29, 2026
    risk 0.57cvss 8.7epss 0.00

    In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

  • CVE-2026-28193HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.00

    In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

  • CVE-2025-57731HigAug 20, 2025
    risk 0.57cvss 8.7epss 0.00

    In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content

  • CVE-2022-24342HigFeb 25, 2022
    risk 0.57cvss 8.8epss 0.03

    In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.

  • CVE-2021-37543HigAug 6, 2021
    risk 0.57cvss 8.8epss 0.01

    In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.

  • CVE-2021-31912HigMay 11, 2021
    risk 0.57cvss 8.8epss 0.01

    In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.

  • CVE-2021-31899HigMay 11, 2021
    risk 0.57cvss 8.8epss 0.01

    In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.

  • CVE-2021-25765HigFeb 3, 2021
    risk 0.57cvss 8.8epss 0.01

    In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.

  • CVE-2020-15825HigAug 8, 2020
    risk 0.57cvss 8.8epss 0.01

    In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.

  • CVE-2020-15824HigAug 8, 2020
    risk 0.57cvss 8.8epss 0.02

    In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by…

  • CVE-2020-15817HigAug 8, 2020
    risk 0.57cvss 8.8epss 0.02

    In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.

  • CVE-2019-15040HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.01

    JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.

  • CVE-2019-12851HigJul 3, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.

  • CVE-2023-45612HigOct 9, 2023
    risk 0.56cvss 8.6epss 0.01

    In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

  • CVE-2026-86502HigSep 7, 2026
    risk 0.55cvss 8.4epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

  • CVE-2026-86492HigSep 7, 2026
    risk 0.55cvss 8.5epss 0.01

    In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

  • CVE-2026-75060HigAug 17, 2026
    risk 0.55cvss 8.4epss 0.00

    In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

  • CVE-2025-64456HigNov 10, 2025
    risk 0.55cvss 8.4epss 0.00

    In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation

  • CVE-2022-28651HigApr 5, 2022
    risk 0.55cvss 8.4epss 0.00

    In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields

  • CVE-2025-59458HigSep 17, 2025
    risk 0.54cvss 8.3epss 0.00

    In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation

  • CVE-2025-43015HigApr 17, 2025
    risk 0.54cvss 8.3epss 0.00

    In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces

  • CVE-2025-43012HigApr 17, 2025
    risk 0.54cvss 8.3epss 0.01

    In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

  • CVE-2026-86479HigSep 7, 2026
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

  • CVE-2026-75051HigAug 17, 2026
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

  • CVE-2026-75048HigAug 17, 2026
    risk 0.53cvss 8.2epss 0.00

    In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

  • CVE-2026-75044HigAug 17, 2026
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

  • CVE-2026-44413HigMay 11, 2026
    risk 0.53cvss 8.2epss 0.00

    In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access

  • CVE-2026-25847HigFeb 9, 2026
    risk 0.53cvss 8.2epss 0.00

    In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible

  • CVE-2025-64685HigNov 10, 2025
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

  • CVE-2025-58334HigAug 28, 2025
    risk 0.53cvss 8.1epss 0.00

    In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

  • CVE-2024-49579HigOct 17, 2024
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

  • CVE-2024-36470HigMay 29, 2024
    risk 0.53cvss 8.1epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases

  • CVE-2022-24335HigFeb 25, 2022
    risk 0.53cvss 8.1epss 0.01

    JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.

  • CVE-2019-9872HigJul 3, 2019
    risk 0.53cvss 8.1epss 0.01

    In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and…

  • CVE-2026-49367HigMay 29, 2026
    risk 0.52cvss 8.0epss 0.01

    In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

  • CVE-2024-54154HigDec 4, 2024
    risk 0.52cvss 8.0epss 0.01

    In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

  • CVE-2026-86504HigSep 7, 2026
    risk 0.51cvss 7.8epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

  • CVE-2026-75056HigAug 17, 2026
    risk 0.51cvss 7.8epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

  • CVE-2026-49366HigMay 29, 2026
    risk 0.51cvss 7.8epss 0.01

    In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

  • CVE-2025-23385HigJan 28, 2025
    risk 0.51cvss 7.8epss 0.00

    In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible

  • CVE-2022-24346HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.00

    In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

  • CVE-2022-24345HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.00

    In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

  • CVE-2021-30005HigMay 11, 2021
    risk 0.51cvss 7.8epss 0.01

    In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

  • CVE-2021-29263HigMay 11, 2021
    risk 0.51cvss 7.8epss 0.00

    In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.

  • CVE-2021-25758HigFeb 3, 2021
    risk 0.51cvss 7.8epss 0.01

    In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.

  • CVE-2019-14960HigOct 1, 2019
    risk 0.51cvss 7.8epss 0.00

    JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.

  • CVE-2018-14878HigAug 13, 2018
    risk 0.51cvss 7.8epss 0.02

    JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.

Page 2 of 13