Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11685 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. | ||
| CVE-2020-11694 | Hig | 0.49 | 7.5 | 0.02 | Apr 10, 2020 | In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3. | ||
| CVE-2020-7907 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2020 | In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections. | ||
| CVE-2020-7914 | Hig | 0.49 | 7.5 | 0.02 | Jan 31, 2020 | In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3. | ||
| CVE-2020-7909 | Hig | 0.49 | 7.5 | 0.01 | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI. | ||
| CVE-2020-7906 | Hig | 0.49 | 7.5 | 0.01 | Jan 30, 2020 | In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3. | ||
| CVE-2020-7905 | Hig | 0.49 | 7.5 | 0.01 | Jan 30, 2020 | Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network. | ||
| CVE-2019-18412 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2020 | JetBrains IDETalk plugin before version 193.4099.10 allows XXE | ||
| CVE-2019-14958 | Hig | 0.49 | 7.5 | 0.02 | Oct 2, 2019 | JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation. | ||
| CVE-2019-15042 | Hig | 0.49 | 7.5 | 0.01 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1. | ||
| CVE-2019-15038 | Hig | 0.49 | 7.5 | 0.01 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1. | ||
| CVE-2019-12841 | Hig | 0.49 | 7.5 | 0.01 | Jul 3, 2019 | Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2. | ||
| CVE-2017-8316 | Hig | 0.49 | 7.5 | 0.02 | Aug 3, 2018 | IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml. | ||
| CVE-2026-41882 | Hig | 0.48 | 7.4 | 0.00 | Apr 30, 2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server | ||
| CVE-2024-41827 | Hig | 0.48 | 7.4 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration | ||
| CVE-2024-31136 | Hig | 0.48 | 7.4 | 0.01 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter | ||
| CVE-2021-43189 | Hig | 0.48 | 7.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. | ||
| CVE-2021-43188 | Hig | 0.48 | 7.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. | ||
| CVE-2020-15822 | Hig | 0.48 | 7.3 | 0.01 | Oct 19, 2020 | In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped. | ||
| CVE-2020-7904 | Hig | 0.48 | 7.4 | 0.01 | Jan 30, 2020 | In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS. | ||
| CVE-2019-18368 | Hig | 0.48 | 7.3 | 0.01 | Oct 31, 2019 | In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. | ||
| CVE-2026-49373 | Hig | 0.47 | 7.1 | 0.27 | May 29, 2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | ||
| CVE-2026-33392 | Hig | 0.47 | 7.2 | 0.00 | Apr 17, 2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass | ||
| CVE-2022-28650 | Hig | 0.47 | 7.3 | 0.01 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI | ||
| CVE-2019-16407 | Hig | 0.47 | 7.3 | 0.00 | Oct 2, 2019 | JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability. | ||
| CVE-2019-15036 | Hig | 0.47 | 7.2 | 0.02 | Oct 2, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1. | ||
| CVE-2019-12847 | Hig | 0.47 | 7.2 | 0.01 | Jul 3, 2019 | In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period. | ||
| CVE-2026-75050 | Hig | 0.46 | 7.1 | 0.01 | Aug 17, 2026 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | ||
| CVE-2026-53915 | Hig | 0.46 | 7.1 | 0.00 | Jun 19, 2026 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | ||
| CVE-2026-49371 | Hig | 0.46 | 7.1 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | ||
| CVE-2025-24458 | Hig | 0.46 | 7.1 | 0.00 | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | ||
| CVE-2022-46829 | Hig | 0.46 | 7.1 | 0.00 | Dec 8, 2022 | In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented. | ||
| CVE-2019-10103 | Hig | 0.46 | 8.1 | 0.01 | Jul 3, 2019 | JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101. | ||
| CVE-2019-10102 | Hig | 0.46 | 8.1 | 0.01 | Jul 3, 2019 | JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30. | ||
| CVE-2019-10101 | Hig | 0.46 | 8.1 | 0.01 | Jul 3, 2019 | JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. | ||
| CVE-2025-43013 | Med | 0.45 | 6.9 | 0.00 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible | ||
| CVE-2022-29821 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible | ||
| CVE-2022-29819 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible | ||
| CVE-2022-29815 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible | ||
| CVE-2022-29814 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible | ||
| CVE-2022-29813 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible | ||
| CVE-2026-86497 | Med | 0.44 | 6.8 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials | ||
| CVE-2026-32229 | Med | 0.44 | 6.8 | 0.00 | Mar 11, 2026 | In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled | ||
| CVE-2025-24456 | Med | 0.44 | 6.7 | 0.00 | Jan 21, 2025 | In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping | ||
| CVE-2024-36365 | Med | 0.44 | 6.8 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent | ||
| CVE-2024-31137 | Med | 0.44 | 6.8 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration | ||
| CVE-2023-45613 | Med | 0.44 | 6.8 | 0.00 | Oct 9, 2023 | In JetBrains Ktor before 2.3.5 server certificates were not verified | ||
| CVE-2022-46831 | Med | 0.43 | 6.6 | 0.00 | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators. | ||
| CVE-2026-86495 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects | ||
| CVE-2026-86493 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards |
- risk 0.49cvss 7.5epss 0.01
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
- risk 0.49cvss 7.5epss 0.02
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
- risk 0.49cvss 7.5epss 0.01
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
- risk 0.49cvss 7.5epss 0.02
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.
- risk 0.49cvss 7.5epss 0.01
Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.
- risk 0.49cvss 7.5epss 0.01
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
- risk 0.49cvss 7.5epss 0.02
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
- risk 0.49cvss 7.5epss 0.01
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.
- risk 0.49cvss 7.5epss 0.02
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
- risk 0.48cvss 7.4epss 0.00
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
- risk 0.48cvss 7.4epss 0.00
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
- risk 0.48cvss 7.4epss 0.01
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
- risk 0.48cvss 7.4epss 0.01
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
- risk 0.48cvss 7.3epss 0.01
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
- risk 0.47cvss 7.1epss 0.27
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
- risk 0.47cvss 7.2epss 0.00
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
- risk 0.47cvss 7.3epss 0.01
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
- risk 0.47cvss 7.3epss 0.00
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
- risk 0.47cvss 7.2epss 0.02
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
- risk 0.47cvss 7.2epss 0.01
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.
- risk 0.46cvss 7.1epss 0.01
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
- risk 0.46cvss 7.1epss 0.00
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
- risk 0.46cvss 7.1epss 0.00
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
- risk 0.46cvss 7.1epss 0.00
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
- risk 0.46cvss 7.1epss 0.00
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
- risk 0.46cvss 8.1epss 0.01
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.
- risk 0.46cvss 8.1epss 0.01
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
- risk 0.46cvss 8.1epss 0.01
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
- risk 0.45cvss 6.9epss 0.00
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
- risk 0.44cvss 6.8epss 0.00
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
- risk 0.44cvss 6.8epss 0.00
In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled
- risk 0.44cvss 6.7epss 0.00
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
- risk 0.44cvss 6.8epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
- risk 0.44cvss 6.8epss 0.00
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
- risk 0.44cvss 6.8epss 0.00
In JetBrains Ktor before 2.3.5 server certificates were not verified
- risk 0.43cvss 6.6epss 0.00
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
Page 4 of 13