VYPR

Vendor CVEs

Jetbrains

All CVEs

650 total · sorted by risk
  • CVE-2020-11685HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

  • CVE-2020-11694HigApr 10, 2020
    risk 0.49cvss 7.5epss 0.02

    In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.

  • CVE-2020-7907HigFeb 21, 2020
    risk 0.49cvss 7.5epss 0.01

    In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.

  • CVE-2020-7914HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.

  • CVE-2020-7909HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.

  • CVE-2020-7906HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.

  • CVE-2020-7905HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.

  • CVE-2019-18412HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    JetBrains IDETalk plugin before version 193.4099.10 allows XXE

  • CVE-2019-14958HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.02

    JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.

  • CVE-2019-15042HigOct 1, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.

  • CVE-2019-15038HigOct 1, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.

  • CVE-2019-12841HigJul 3, 2019
    risk 0.49cvss 7.5epss 0.01

    Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.

  • CVE-2017-8316HigAug 3, 2018
    risk 0.49cvss 7.5epss 0.02

    IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.

  • CVE-2026-41882HigApr 30, 2026
    risk 0.48cvss 7.4epss 0.00

    In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

  • CVE-2024-41827HigJul 22, 2024
    risk 0.48cvss 7.4epss 0.00

    In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration

  • CVE-2024-31136HigMar 28, 2024
    risk 0.48cvss 7.4epss 0.01

    In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

  • CVE-2021-43189HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

  • CVE-2021-43188HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

  • CVE-2020-15822HigOct 19, 2020
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.

  • CVE-2020-7904HigJan 30, 2020
    risk 0.48cvss 7.4epss 0.01

    In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

  • CVE-2019-18368HigOct 31, 2019
    risk 0.48cvss 7.3epss 0.01

    In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.

  • CVE-2026-49373HigMay 29, 2026
    risk 0.47cvss 7.1epss 0.27

    In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

  • CVE-2026-33392HigApr 17, 2026
    risk 0.47cvss 7.2epss 0.00

    In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

  • CVE-2022-28650HigApr 5, 2022
    risk 0.47cvss 7.3epss 0.01

    In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

  • CVE-2019-16407HigOct 2, 2019
    risk 0.47cvss 7.3epss 0.00

    JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.

  • CVE-2019-15036HigOct 2, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.

  • CVE-2019-12847HigJul 3, 2019
    risk 0.47cvss 7.2epss 0.01

    In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.

  • CVE-2026-75050HigAug 17, 2026
    risk 0.46cvss 7.1epss 0.01

    In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

  • CVE-2026-53915HigJun 19, 2026
    risk 0.46cvss 7.1epss 0.00

    In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

  • CVE-2026-49371HigMay 29, 2026
    risk 0.46cvss 7.1epss 0.00

    In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

  • CVE-2025-24458HigJan 21, 2025
    risk 0.46cvss 7.1epss 0.00

    In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

  • CVE-2022-46829HigDec 8, 2022
    risk 0.46cvss 7.1epss 0.00

    In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.

  • CVE-2019-10103HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.

  • CVE-2019-10102HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.

  • CVE-2019-10101HigJul 3, 2019
    risk 0.46cvss 8.1epss 0.01

    JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.

  • CVE-2025-43013MedApr 17, 2025
    risk 0.45cvss 6.9epss 0.00

    In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

  • CVE-2022-29821MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

  • CVE-2022-29819MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible

  • CVE-2022-29815MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible

  • CVE-2022-29814MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible

  • CVE-2022-29813MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible

  • CVE-2026-86497MedSep 7, 2026
    risk 0.44cvss 6.8epss 0.00

    In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

  • CVE-2026-32229MedMar 11, 2026
    risk 0.44cvss 6.8epss 0.00

    In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled

  • CVE-2025-24456MedJan 21, 2025
    risk 0.44cvss 6.7epss 0.00

    In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

  • CVE-2024-36365MedMay 29, 2024
    risk 0.44cvss 6.8epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

  • CVE-2024-31137MedMar 28, 2024
    risk 0.44cvss 6.8epss 0.00

    In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

  • CVE-2023-45613MedOct 9, 2023
    risk 0.44cvss 6.8epss 0.00

    In JetBrains Ktor before 2.3.5 server certificates were not verified

  • CVE-2022-46831MedDec 8, 2022
    risk 0.43cvss 6.6epss 0.00

    In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.

  • CVE-2026-86495MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

  • CVE-2026-86493MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

Page 4 of 13