VYPR

Vendor CVEs

Jetbrains

All CVEs

603 total · sorted by risk
  • CVE-2024-31136HigMar 28, 2024
    risk 0.48cvss 7.4epss 0.01

    In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

  • CVE-2021-43189HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

  • CVE-2021-43188HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

  • CVE-2020-15822HigOct 19, 2020
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.

  • CVE-2020-7904HigJan 30, 2020
    risk 0.48cvss 7.4epss 0.01

    In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

  • CVE-2019-18368HigOct 31, 2019
    risk 0.48cvss 7.3epss 0.01

    In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.

  • CVE-2026-49373HigMay 29, 2026
    risk 0.47cvss 7.1epss 0.13

    In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

  • CVE-2026-33392HigApr 17, 2026
    risk 0.47cvss 7.2epss 0.00

    In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

  • CVE-2022-28650HigApr 5, 2022
    risk 0.47cvss 7.3epss 0.01

    In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

  • CVE-2019-16407HigOct 2, 2019
    risk 0.47cvss 7.3epss 0.00

    JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.

  • CVE-2019-15036HigOct 2, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.

  • CVE-2019-12847HigJul 3, 2019
    risk 0.47cvss 7.2epss 0.01

    In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.

  • CVE-2026-53915HigJun 19, 2026
    risk 0.46cvss 7.1epss 0.00

    In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

  • CVE-2026-49371HigMay 29, 2026
    risk 0.46cvss 7.1epss 0.00

    In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

  • CVE-2025-24458HigJan 21, 2025
    risk 0.46cvss 7.1epss 0.00

    In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

  • CVE-2022-46829HigDec 8, 2022
    risk 0.46cvss 7.1epss 0.00

    In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.

  • CVE-2019-10103HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.

  • CVE-2019-10102HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.

  • CVE-2019-10101HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.02

    JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.

  • CVE-2025-43013MedApr 17, 2025
    risk 0.45cvss 6.9epss 0.00

    In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

  • CVE-2022-29821MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

  • CVE-2022-29819MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible

  • CVE-2022-29815MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible

  • CVE-2022-29814MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible

  • CVE-2022-29813MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible

  • CVE-2026-32229MedMar 11, 2026
    risk 0.44cvss 6.8epss 0.00

    In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled

  • CVE-2025-24456MedJan 21, 2025
    risk 0.44cvss 6.7epss 0.00

    In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

  • CVE-2024-36365MedMay 29, 2024
    risk 0.44cvss 6.8epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

  • CVE-2024-31137MedMar 28, 2024
    risk 0.44cvss 6.8epss 0.00

    In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

  • CVE-2023-45613MedOct 9, 2023
    risk 0.44cvss 6.8epss 0.00

    In JetBrains Ktor before 2.3.5 server certificates were not verified

  • CVE-2022-46831MedDec 8, 2022
    risk 0.43cvss 6.6epss 0.00

    In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.

  • CVE-2026-49386MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

  • CVE-2026-49385MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

  • CVE-2026-49379MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

  • CVE-2026-49376MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

  • CVE-2026-25846MedFeb 9, 2026
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

  • CVE-2025-68267MedDec 16, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

  • CVE-2025-57729MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

  • CVE-2025-57728MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

  • CVE-2025-24461MedJan 21, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint

  • CVE-2024-41824MedJul 22, 2024
    risk 0.42cvss 6.4epss 0.00

    In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

  • CVE-2024-36377MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

  • CVE-2024-36376MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

  • CVE-2024-36364MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

  • CVE-2024-36362MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

  • CVE-2024-31134MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

  • CVE-2024-28230MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

  • CVE-2024-28229MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

  • CVE-2023-38068MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

  • CVE-2015-1313MedJun 29, 2023
    risk 0.42cvss 6.5epss 0.01

    JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.

Page 4 of 13