VYPR

Vendor CVEs

Jetbrains

All CVEs

650 total · sorted by risk
  • CVE-2026-86490MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

  • CVE-2026-86489MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations

  • CVE-2026-86488MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches

  • CVE-2026-75049MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

  • CVE-2026-75047MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

  • CVE-2026-49386MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

  • CVE-2026-49385MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

  • CVE-2026-49379MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

  • CVE-2026-49376MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

  • CVE-2026-25846MedFeb 9, 2026
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

  • CVE-2025-68267MedDec 16, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

  • CVE-2025-57729MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

  • CVE-2025-57728MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

  • CVE-2025-24461MedJan 21, 2025
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint

  • CVE-2024-41824MedJul 22, 2024
    risk 0.42cvss 6.4epss 0.00

    In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

  • CVE-2024-36377MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

  • CVE-2024-36376MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

  • CVE-2024-36364MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

  • CVE-2024-36362MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

  • CVE-2024-31134MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

  • CVE-2024-28230MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

  • CVE-2024-28229MedMar 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

  • CVE-2023-38068MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

  • CVE-2015-1313MedJun 29, 2023
    risk 0.42cvss 6.5epss 0.01

    JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.

  • CVE-2022-44624MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters

  • CVE-2022-44623MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings

  • CVE-2022-24337MedFeb 25, 2022
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.

  • CVE-2022-24333MedFeb 25, 2022
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.

  • CVE-2022-24328MedFeb 25, 2022
    risk 0.42cvss 6.5epss 0.01

    In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.

  • CVE-2021-37540MedAug 6, 2021
    risk 0.42cvss 6.5epss 0.01

    In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.

  • CVE-2021-25759MedFeb 3, 2021
    risk 0.42cvss 6.5epss 0.01

    In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.

  • CVE-2020-26129MedNov 16, 2020
    risk 0.42cvss 6.5epss 0.01

    In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.

  • CVE-2020-24618MedAug 27, 2020
    risk 0.42cvss 6.5epss 0.02

    In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.

  • CVE-2020-15828MedAug 8, 2020
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.

  • CVE-2020-15821MedAug 8, 2020
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.

  • CVE-2020-11689MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.

  • CVE-2026-75054MedAug 17, 2026
    risk 0.41cvss 6.3epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

  • CVE-2026-32745MedMar 13, 2026
    risk 0.41cvss 6.3epss 0.00

    In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings

  • CVE-2024-56351MedDec 20, 2024
    risk 0.41cvss 6.3epss 0.00

    In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles

  • CVE-2024-52555MedNov 15, 2024
    risk 0.41cvss 6.3epss 0.00

    In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script

  • CVE-2024-38506MedJun 18, 2024
    risk 0.41cvss 6.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

  • CVE-2023-51655MedDec 21, 2023
    risk 0.41cvss 6.3epss 0.00

    In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration

  • CVE-2026-75057MedAug 17, 2026
    risk 0.40cvss 6.2epss 0.00

    In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

  • CVE-2026-49384MedMay 29, 2026
    risk 0.40cvss 6.1epss 0.00

    In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

  • CVE-2026-49375MedMay 29, 2026
    risk 0.40cvss 6.1epss 0.00

    In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

  • CVE-2025-54527MedJul 28, 2025
    risk 0.40cvss 6.1epss 0.00

    In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

  • CVE-2025-43014MedApr 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation

  • CVE-2024-31135MedMar 28, 2024
    risk 0.40cvss 6.1epss 0.00

    In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

  • CVE-2024-24941MedFeb 6, 2024
    risk 0.40cvss 6.1epss 0.00

    In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

  • CVE-2022-48433MedMar 29, 2023
    risk 0.40cvss 6.1epss 0.01

    In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.

Page 5 of 13