Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-31136 | Hig | 0.48 | 7.4 | 0.01 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter | ||
| CVE-2021-43189 | Hig | 0.48 | 7.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. | ||
| CVE-2021-43188 | Hig | 0.48 | 7.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. | ||
| CVE-2020-15822 | Hig | 0.48 | 7.3 | 0.01 | Oct 19, 2020 | In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped. | ||
| CVE-2020-7904 | Hig | 0.48 | 7.4 | 0.01 | Jan 30, 2020 | In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS. | ||
| CVE-2019-18368 | Hig | 0.48 | 7.3 | 0.01 | Oct 31, 2019 | In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. | ||
| CVE-2026-49373 | Hig | 0.47 | 7.1 | 0.13 | May 29, 2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | ||
| CVE-2026-33392 | Hig | 0.47 | 7.2 | 0.00 | Apr 17, 2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass | ||
| CVE-2022-28650 | Hig | 0.47 | 7.3 | 0.01 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI | ||
| CVE-2019-16407 | Hig | 0.47 | 7.3 | 0.00 | Oct 2, 2019 | JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability. | ||
| CVE-2019-15036 | Hig | 0.47 | 7.2 | 0.02 | Oct 2, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1. | ||
| CVE-2019-12847 | Hig | 0.47 | 7.2 | 0.01 | Jul 3, 2019 | In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period. | ||
| CVE-2026-53915 | Hig | 0.46 | 7.1 | 0.00 | Jun 19, 2026 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | ||
| CVE-2026-49371 | Hig | 0.46 | 7.1 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | ||
| CVE-2025-24458 | Hig | 0.46 | 7.1 | 0.00 | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | ||
| CVE-2022-46829 | Hig | 0.46 | 7.1 | 0.00 | Dec 8, 2022 | In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented. | ||
| CVE-2019-10103 | Hig | 0.46 | 8.1 | 0.01 | Jul 3, 2019 | JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101. | ||
| CVE-2019-10102 | Hig | 0.46 | 8.1 | 0.01 | Jul 3, 2019 | JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30. | ||
| CVE-2019-10101 | Hig | 0.46 | 8.1 | 0.02 | Jul 3, 2019 | JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. | ||
| CVE-2025-43013 | Med | 0.45 | 6.9 | 0.00 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible | ||
| CVE-2022-29821 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible | ||
| CVE-2022-29819 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible | ||
| CVE-2022-29815 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible | ||
| CVE-2022-29814 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible | ||
| CVE-2022-29813 | Med | 0.45 | 6.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible | ||
| CVE-2026-32229 | Med | 0.44 | 6.8 | 0.00 | Mar 11, 2026 | In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled | ||
| CVE-2025-24456 | Med | 0.44 | 6.7 | 0.00 | Jan 21, 2025 | In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping | ||
| CVE-2024-36365 | Med | 0.44 | 6.8 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent | ||
| CVE-2024-31137 | Med | 0.44 | 6.8 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration | ||
| CVE-2023-45613 | Med | 0.44 | 6.8 | 0.00 | Oct 9, 2023 | In JetBrains Ktor before 2.3.5 server certificates were not verified | ||
| CVE-2022-46831 | Med | 0.43 | 6.6 | 0.00 | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators. | ||
| CVE-2026-49386 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas | ||
| CVE-2026-49385 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts | ||
| CVE-2026-49379 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | ||
| CVE-2026-49376 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin | ||
| CVE-2026-25846 | Med | 0.42 | 6.5 | 0.01 | Feb 9, 2026 | In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs | ||
| CVE-2025-68267 | Med | 0.42 | 6.5 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token | ||
| CVE-2025-57729 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start | ||
| CVE-2025-57728 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files | ||
| CVE-2025-24461 | Med | 0.42 | 6.5 | 0.00 | Jan 21, 2025 | In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint | ||
| CVE-2024-41824 | Med | 0.42 | 6.4 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases | ||
| CVE-2024-36377 | Med | 0.42 | 6.5 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions | ||
| CVE-2024-36376 | Med | 0.42 | 6.5 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions | ||
| CVE-2024-36364 | Med | 0.42 | 6.5 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible | ||
| CVE-2024-36362 | Med | 0.42 | 6.5 | 0.01 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible | ||
| CVE-2024-31134 | Med | 0.42 | 6.5 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled | ||
| CVE-2024-28230 | Med | 0.42 | 6.5 | 0.01 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions | ||
| CVE-2024-28229 | Med | 0.42 | 6.5 | 0.01 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles | ||
| CVE-2023-38068 | Med | 0.42 | 6.5 | 0.01 | Jul 12, 2023 | In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms | ||
| CVE-2015-1313 | Med | 0.42 | 6.5 | 0.01 | Jun 29, 2023 | JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request. |
- risk 0.48cvss 7.4epss 0.01
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
- risk 0.48cvss 7.3epss 0.01
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
- risk 0.48cvss 7.4epss 0.01
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
- risk 0.48cvss 7.3epss 0.01
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
- risk 0.47cvss 7.1epss 0.13
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
- risk 0.47cvss 7.2epss 0.00
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
- risk 0.47cvss 7.3epss 0.01
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
- risk 0.47cvss 7.3epss 0.00
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
- risk 0.47cvss 7.2epss 0.02
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
- risk 0.47cvss 7.2epss 0.01
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.
- risk 0.46cvss 7.1epss 0.00
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
- risk 0.46cvss 7.1epss 0.00
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
- risk 0.46cvss 7.1epss 0.00
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
- risk 0.46cvss 7.1epss 0.00
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
- risk 0.46cvss 8.1epss 0.01
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.
- risk 0.46cvss 8.1epss 0.01
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
- risk 0.46cvss 8.1epss 0.02
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
- risk 0.45cvss 6.9epss 0.00
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
- risk 0.45cvss 6.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
- risk 0.44cvss 6.8epss 0.00
In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled
- risk 0.44cvss 6.7epss 0.00
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
- risk 0.44cvss 6.8epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
- risk 0.44cvss 6.8epss 0.00
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
- risk 0.44cvss 6.8epss 0.00
In JetBrains Ktor before 2.3.5 server certificates were not verified
- risk 0.43cvss 6.6epss 0.00
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
- risk 0.42cvss 6.5epss 0.00
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token
- risk 0.42cvss 6.5epss 0.00
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
- risk 0.42cvss 6.5epss 0.00
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
- risk 0.42cvss 6.4epss 0.00
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
- risk 0.42cvss 6.5epss 0.01
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.
Page 4 of 13