Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-28193 | Hig | 0.57 | 8.8 | 0.00 | Feb 25, 2026 | In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint | ||
| CVE-2025-57731 | Hig | 0.57 | 8.7 | 0.00 | Aug 20, 2025 | In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content | ||
| CVE-2022-24342 | Hig | 0.57 | 8.8 | 0.03 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. | ||
| CVE-2021-37543 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2021 | In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects. | ||
| CVE-2021-31912 | Hig | 0.57 | 8.8 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. | ||
| CVE-2021-31899 | Hig | 0.57 | 8.8 | 0.01 | May 11, 2021 | In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode. | ||
| CVE-2021-25765 | Hig | 0.57 | 8.8 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible. | ||
| CVE-2020-15825 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges. | ||
| CVE-2020-15824 | Hig | 0.57 | 8.8 | 0.02 | Aug 8, 2020 | In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by… | ||
| CVE-2020-15817 | Hig | 0.57 | 8.8 | 0.02 | Aug 8, 2020 | In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues. | ||
| CVE-2019-15040 | Hig | 0.57 | 8.8 | 0.01 | Oct 2, 2019 | JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page. | ||
| CVE-2019-12851 | Hig | 0.57 | 8.8 | 0.01 | Jul 3, 2019 | A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852. | ||
| CVE-2023-45612 | Hig | 0.56 | 8.6 | 0.01 | Oct 9, 2023 | In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE | ||
| CVE-2025-64456 | Hig | 0.55 | 8.4 | 0.00 | Nov 10, 2025 | In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation | ||
| CVE-2022-28651 | Hig | 0.55 | 8.4 | 0.00 | Apr 5, 2022 | In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields | ||
| CVE-2025-59458 | Hig | 0.54 | 8.3 | 0.00 | Sep 17, 2025 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation | ||
| CVE-2025-43015 | Hig | 0.54 | 8.3 | 0.00 | Apr 17, 2025 | In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces | ||
| CVE-2025-43012 | Hig | 0.54 | 8.3 | 0.01 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible | ||
| CVE-2026-44413 | Hig | 0.53 | 8.2 | 0.00 | May 11, 2026 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access | ||
| CVE-2026-25847 | Hig | 0.53 | 8.2 | 0.00 | Feb 9, 2026 | In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible | ||
| CVE-2025-64685 | Hig | 0.53 | 8.1 | 0.00 | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure | ||
| CVE-2025-58334 | Hig | 0.53 | 8.1 | 0.00 | Aug 28, 2025 | In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves | ||
| CVE-2024-49579 | Hig | 0.53 | 8.1 | 0.00 | Oct 17, 2024 | In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests | ||
| CVE-2024-36470 | Hig | 0.53 | 8.1 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases | ||
| CVE-2022-24335 | Hig | 0.53 | 8.1 | 0.01 | Feb 25, 2022 | JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC. | ||
| CVE-2019-9872 | Hig | 0.53 | 8.1 | 0.01 | Jul 3, 2019 | In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and… | ||
| CVE-2026-49367 | Hig | 0.52 | 8.0 | 0.00 | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account | ||
| CVE-2024-54154 | Hig | 0.52 | 8.0 | 0.01 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | ||
| CVE-2026-49366 | Hig | 0.51 | 7.8 | 0.00 | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion | ||
| CVE-2025-23385 | Hig | 0.51 | 7.8 | 0.00 | Jan 28, 2025 | In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible | ||
| CVE-2022-24346 | Hig | 0.51 | 7.8 | 0.00 | Feb 25, 2022 | In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible. | ||
| CVE-2022-24345 | Hig | 0.51 | 7.8 | 0.00 | Feb 25, 2022 | In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible. | ||
| CVE-2021-30005 | Hig | 0.51 | 7.8 | 0.01 | May 11, 2021 | In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS. | ||
| CVE-2021-29263 | Hig | 0.51 | 7.8 | 0.00 | May 11, 2021 | In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS. | ||
| CVE-2021-25758 | Hig | 0.51 | 7.8 | 0.01 | Feb 3, 2021 | In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution. | ||
| CVE-2019-14960 | Hig | 0.51 | 7.8 | 0.00 | Oct 1, 2019 | JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file. | ||
| CVE-2018-14878 | Hig | 0.51 | 7.8 | 0.02 | Aug 13, 2018 | JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data. | ||
| CVE-2025-59457 | Hig | 0.50 | 7.7 | 0.01 | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows | ||
| CVE-2025-54531 | Hig | 0.50 | 7.7 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows | ||
| CVE-2025-48391 | Hig | 0.50 | 7.7 | 0.00 | May 20, 2025 | In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API | ||
| CVE-2025-26492 | Hig | 0.50 | 7.7 | 0.00 | Feb 11, 2025 | In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources | ||
| CVE-2026-49374 | Hig | 0.49 | 7.6 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | ||
| CVE-2026-49372 | Hig | 0.49 | 7.5 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | ||
| CVE-2025-57732 | Hig | 0.49 | 7.5 | 0.00 | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership | ||
| CVE-2025-54530 | Hig | 0.49 | 7.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions | ||
| CVE-2025-53959 | Hig | 0.49 | 7.6 | 0.00 | Jul 15, 2025 | In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible | ||
| CVE-2024-43114 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2024 | In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions | ||
| CVE-2023-35053 | Hig | 0.49 | 7.5 | 0.01 | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms | ||
| CVE-2022-48476 | Hig | 0.49 | 7.5 | 0.01 | Apr 24, 2023 | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible | ||
| CVE-2022-40978 | Hig | 0.49 | 7.5 | 0.00 | Sep 19, 2022 | The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking |
- risk 0.57cvss 8.8epss 0.00
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
- risk 0.57cvss 8.7epss 0.00
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
- risk 0.57cvss 8.8epss 0.03
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
- risk 0.57cvss 8.8epss 0.01
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
- risk 0.57cvss 8.8epss 0.01
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
- risk 0.57cvss 8.8epss 0.01
In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.
- risk 0.57cvss 8.8epss 0.01
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
- risk 0.57cvss 8.8epss 0.01
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
- risk 0.57cvss 8.8epss 0.02
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by…
- risk 0.57cvss 8.8epss 0.02
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
- risk 0.57cvss 8.8epss 0.01
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
- risk 0.57cvss 8.8epss 0.01
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
- risk 0.56cvss 8.6epss 0.01
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
- risk 0.55cvss 8.4epss 0.00
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
- risk 0.55cvss 8.4epss 0.00
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
- risk 0.54cvss 8.3epss 0.00
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation
- risk 0.54cvss 8.3epss 0.00
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
- risk 0.54cvss 8.3epss 0.01
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
- risk 0.53cvss 8.2epss 0.00
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
- risk 0.53cvss 8.2epss 0.00
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
- risk 0.53cvss 8.1epss 0.00
In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
- risk 0.53cvss 8.1epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
- risk 0.53cvss 8.1epss 0.01
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.
- risk 0.53cvss 8.1epss 0.01
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and…
- risk 0.52cvss 8.0epss 0.00
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
- risk 0.52cvss 8.0epss 0.01
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
- risk 0.51cvss 7.8epss 0.00
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.
- risk 0.51cvss 7.8epss 0.01
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
- risk 0.51cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.
- risk 0.51cvss 7.8epss 0.01
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
- risk 0.51cvss 7.8epss 0.00
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
- risk 0.51cvss 7.8epss 0.02
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.
- risk 0.50cvss 7.7epss 0.01
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
- risk 0.50cvss 7.7epss 0.00
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
- risk 0.50cvss 7.7epss 0.00
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
- risk 0.50cvss 7.7epss 0.00
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
- risk 0.49cvss 7.6epss 0.00
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
- risk 0.49cvss 7.6epss 0.00
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
- risk 0.49cvss 7.5epss 0.01
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
- risk 0.49cvss 7.5epss 0.00
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
Page 2 of 13