Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37549 | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient. | ||
| CVE-2026-86482 | Hig | 0.57 | 8.8 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation | ||
| CVE-2026-65906 | Hig | 0.57 | 8.8 | 0.01 | Jul 23, 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | ||
| CVE-2026-49368 | Hig | 0.57 | 8.7 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | ||
| CVE-2026-28193 | Hig | 0.57 | 8.8 | 0.00 | Feb 25, 2026 | In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint | ||
| CVE-2025-57731 | Hig | 0.57 | 8.7 | 0.00 | Aug 20, 2025 | In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content | ||
| CVE-2022-24342 | Hig | 0.57 | 8.8 | 0.03 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. | ||
| CVE-2021-37543 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2021 | In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects. | ||
| CVE-2021-31912 | Hig | 0.57 | 8.8 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. | ||
| CVE-2021-31899 | Hig | 0.57 | 8.8 | 0.01 | May 11, 2021 | In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode. | ||
| CVE-2021-25765 | Hig | 0.57 | 8.8 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible. | ||
| CVE-2020-15825 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges. | ||
| CVE-2020-15824 | Hig | 0.57 | 8.8 | 0.02 | Aug 8, 2020 | In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by… | ||
| CVE-2020-15817 | Hig | 0.57 | 8.8 | 0.02 | Aug 8, 2020 | In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues. | ||
| CVE-2019-15040 | Hig | 0.57 | 8.8 | 0.01 | Oct 2, 2019 | JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page. | ||
| CVE-2019-12851 | Hig | 0.57 | 8.8 | 0.01 | Jul 3, 2019 | A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852. | ||
| CVE-2023-45612 | Hig | 0.56 | 8.6 | 0.01 | Oct 9, 2023 | In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE | ||
| CVE-2026-86502 | Hig | 0.55 | 8.4 | 0.00 | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts | ||
| CVE-2026-86492 | Hig | 0.55 | 8.5 | 0.01 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens | ||
| CVE-2026-75060 | Hig | 0.55 | 8.4 | 0.00 | Aug 17, 2026 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools | ||
| CVE-2025-64456 | Hig | 0.55 | 8.4 | 0.00 | Nov 10, 2025 | In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation | ||
| CVE-2022-28651 | Hig | 0.55 | 8.4 | 0.00 | Apr 5, 2022 | In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields | ||
| CVE-2025-59458 | Hig | 0.54 | 8.3 | 0.00 | Sep 17, 2025 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation | ||
| CVE-2025-43015 | Hig | 0.54 | 8.3 | 0.00 | Apr 17, 2025 | In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces | ||
| CVE-2025-43012 | Hig | 0.54 | 8.3 | 0.01 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible | ||
| CVE-2026-86479 | Hig | 0.53 | 8.1 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | ||
| CVE-2026-75051 | Hig | 0.53 | 8.1 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | ||
| CVE-2026-75048 | Hig | 0.53 | 8.2 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | ||
| CVE-2026-75044 | Hig | 0.53 | 8.1 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | ||
| CVE-2026-44413 | Hig | 0.53 | 8.2 | 0.00 | May 11, 2026 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access | ||
| CVE-2026-25847 | Hig | 0.53 | 8.2 | 0.00 | Feb 9, 2026 | In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible | ||
| CVE-2025-64685 | Hig | 0.53 | 8.1 | 0.00 | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure | ||
| CVE-2025-58334 | Hig | 0.53 | 8.1 | 0.00 | Aug 28, 2025 | In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves | ||
| CVE-2024-49579 | Hig | 0.53 | 8.1 | 0.00 | Oct 17, 2024 | In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests | ||
| CVE-2024-36470 | Hig | 0.53 | 8.1 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases | ||
| CVE-2022-24335 | Hig | 0.53 | 8.1 | 0.01 | Feb 25, 2022 | JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC. | ||
| CVE-2019-9872 | Hig | 0.53 | 8.1 | 0.01 | Jul 3, 2019 | In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and… | ||
| CVE-2026-49367 | Hig | 0.52 | 8.0 | 0.01 | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account | ||
| CVE-2024-54154 | Hig | 0.52 | 8.0 | 0.01 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | ||
| CVE-2026-86504 | Hig | 0.51 | 7.8 | 0.00 | Sep 7, 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution | ||
| CVE-2026-75056 | Hig | 0.51 | 7.8 | 0.00 | Aug 17, 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | ||
| CVE-2026-49366 | Hig | 0.51 | 7.8 | 0.01 | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion | ||
| CVE-2025-23385 | Hig | 0.51 | 7.8 | 0.00 | Jan 28, 2025 | In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible | ||
| CVE-2022-24346 | Hig | 0.51 | 7.8 | 0.00 | Feb 25, 2022 | In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible. | ||
| CVE-2022-24345 | Hig | 0.51 | 7.8 | 0.00 | Feb 25, 2022 | In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible. | ||
| CVE-2021-30005 | Hig | 0.51 | 7.8 | 0.01 | May 11, 2021 | In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS. | ||
| CVE-2021-29263 | Hig | 0.51 | 7.8 | 0.00 | May 11, 2021 | In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS. | ||
| CVE-2021-25758 | Hig | 0.51 | 7.8 | 0.01 | Feb 3, 2021 | In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution. | ||
| CVE-2019-14960 | Hig | 0.51 | 7.8 | 0.00 | Oct 1, 2019 | JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file. | ||
| CVE-2018-14878 | Hig | 0.51 | 7.8 | 0.02 | Aug 13, 2018 | JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data. |
- risk 0.59cvss 9.1epss 0.01
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
- risk 0.57cvss 8.8epss 0.00
In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
- risk 0.57cvss 8.8epss 0.01
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
- risk 0.57cvss 8.7epss 0.00
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
- risk 0.57cvss 8.8epss 0.00
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
- risk 0.57cvss 8.7epss 0.00
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
- risk 0.57cvss 8.8epss 0.03
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
- risk 0.57cvss 8.8epss 0.01
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
- risk 0.57cvss 8.8epss 0.01
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
- risk 0.57cvss 8.8epss 0.01
In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.
- risk 0.57cvss 8.8epss 0.01
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
- risk 0.57cvss 8.8epss 0.01
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
- risk 0.57cvss 8.8epss 0.02
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by…
- risk 0.57cvss 8.8epss 0.02
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
- risk 0.57cvss 8.8epss 0.01
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
- risk 0.57cvss 8.8epss 0.01
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
- risk 0.56cvss 8.6epss 0.01
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
- risk 0.55cvss 8.4epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
- risk 0.55cvss 8.5epss 0.01
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
- risk 0.55cvss 8.4epss 0.00
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
- risk 0.55cvss 8.4epss 0.00
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
- risk 0.55cvss 8.4epss 0.00
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
- risk 0.54cvss 8.3epss 0.00
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation
- risk 0.54cvss 8.3epss 0.00
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
- risk 0.54cvss 8.3epss 0.01
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
- risk 0.53cvss 8.2epss 0.00
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
- risk 0.53cvss 8.2epss 0.00
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
- risk 0.53cvss 8.2epss 0.00
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
- risk 0.53cvss 8.1epss 0.00
In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
- risk 0.53cvss 8.1epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
- risk 0.53cvss 8.1epss 0.01
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.
- risk 0.53cvss 8.1epss 0.01
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and…
- risk 0.52cvss 8.0epss 0.01
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
- risk 0.52cvss 8.0epss 0.01
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
- risk 0.51cvss 7.8epss 0.01
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
- risk 0.51cvss 7.8epss 0.00
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.
- risk 0.51cvss 7.8epss 0.01
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.
- risk 0.51cvss 7.8epss 0.01
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
- risk 0.51cvss 7.8epss 0.00
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
- risk 0.51cvss 7.8epss 0.02
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.
Page 2 of 13