Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-86498 | Hig | 0.50 | 7.7 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission | ||
| CVE-2026-86494 | Hig | 0.50 | 7.7 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues | ||
| CVE-2025-59457 | Hig | 0.50 | 7.7 | 0.01 | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows | ||
| CVE-2025-54531 | Hig | 0.50 | 7.7 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows | ||
| CVE-2025-48391 | Hig | 0.50 | 7.7 | 0.00 | May 20, 2025 | In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API | ||
| CVE-2025-26492 | Hig | 0.50 | 7.7 | 0.00 | Feb 11, 2025 | In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources | ||
| CVE-2026-49374 | Hig | 0.49 | 7.6 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | ||
| CVE-2026-49372 | Hig | 0.49 | 7.5 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | ||
| CVE-2025-57732 | Hig | 0.49 | 7.5 | 0.00 | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership | ||
| CVE-2025-54530 | Hig | 0.49 | 7.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions | ||
| CVE-2025-53959 | Hig | 0.49 | 7.6 | 0.00 | Jul 15, 2025 | In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible | ||
| CVE-2024-43114 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2024 | In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions | ||
| CVE-2023-35053 | Hig | 0.49 | 7.5 | 0.01 | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms | ||
| CVE-2022-48476 | Hig | 0.49 | 7.5 | 0.01 | Apr 24, 2023 | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible | ||
| CVE-2022-40978 | Hig | 0.49 | 7.5 | 0.00 | Sep 19, 2022 | The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking | ||
| CVE-2022-25264 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases. | ||
| CVE-2022-24341 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user. | ||
| CVE-2022-24327 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. | ||
| CVE-2021-43182 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. | ||
| CVE-2021-43180 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. | ||
| CVE-2021-43203 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly. | ||
| CVE-2021-43196 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. | ||
| CVE-2021-37553 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. | ||
| CVE-2021-37550 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. | ||
| CVE-2021-37548 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS. | ||
| CVE-2021-37545 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made. | ||
| CVE-2021-31913 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange. | ||
| CVE-2021-31910 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. | ||
| CVE-2021-31898 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. | ||
| CVE-2021-30482 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly | ||
| CVE-2021-31905 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible. | ||
| CVE-2021-31902 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly. | ||
| CVE-2021-31901 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group. | ||
| CVE-2021-30504 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation. | ||
| CVE-2021-30006 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure. | ||
| CVE-2021-26310 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible. | ||
| CVE-2021-25776 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters. | ||
| CVE-2021-25769 | Hig | 0.49 | 7.5 | 0.02 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments. | ||
| CVE-2020-35667 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2021 | JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials. | ||
| CVE-2020-27623 | Hig | 0.49 | 7.5 | 0.01 | Nov 16, 2020 | JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances. | ||
| CVE-2020-25209 | Hig | 0.49 | 7.5 | 0.02 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API. | ||
| CVE-2020-25013 | Hig | 0.49 | 7.5 | 0.01 | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler. | ||
| CVE-2020-15827 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2020 | In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file. | ||
| CVE-2020-15823 | Hig | 0.49 | 7.5 | 0.02 | Aug 8, 2020 | JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component. | ||
| CVE-2019-19704 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2020 | In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm. | ||
| CVE-2020-11795 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains Space through 2020-04-22, the session timeout period was configured improperly. | ||
| CVE-2020-11693 | Hig | 0.49 | 7.5 | 0.02 | Apr 22, 2020 | JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue. | ||
| CVE-2020-11691 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible. | ||
| CVE-2020-11688 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session. | ||
| CVE-2020-11687 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages. |
- risk 0.50cvss 7.7epss 0.00
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
- risk 0.50cvss 7.7epss 0.00
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
- risk 0.50cvss 7.7epss 0.01
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
- risk 0.50cvss 7.7epss 0.00
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
- risk 0.50cvss 7.7epss 0.00
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
- risk 0.50cvss 7.7epss 0.00
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
- risk 0.49cvss 7.6epss 0.00
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
- risk 0.49cvss 7.6epss 0.00
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
- risk 0.49cvss 7.5epss 0.01
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
- risk 0.49cvss 7.5epss 0.00
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
- risk 0.49cvss 7.5epss 0.01
In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
- risk 0.49cvss 7.5epss 0.02
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
- risk 0.49cvss 7.5epss 0.01
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
- risk 0.49cvss 7.5epss 0.02
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
- risk 0.49cvss 7.5epss 0.01
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
- risk 0.49cvss 7.5epss 0.01
JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
- risk 0.49cvss 7.5epss 0.01
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
- risk 0.49cvss 7.5epss 0.01
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
Page 3 of 13