Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44624 | Med | 0.42 | 6.5 | 0.01 | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters | ||
| CVE-2022-44623 | Med | 0.42 | 6.5 | 0.01 | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings | ||
| CVE-2022-24337 | Med | 0.42 | 6.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions. | ||
| CVE-2022-24333 | Med | 0.42 | 6.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible. | ||
| CVE-2022-24328 | Med | 0.42 | 6.5 | 0.01 | Feb 25, 2022 | In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS. | ||
| CVE-2021-37540 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2021 | In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used. | ||
| CVE-2021-25759 | Med | 0.42 | 6.5 | 0.01 | Feb 3, 2021 | In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user. | ||
| CVE-2020-26129 | Med | 0.42 | 6.5 | 0.01 | Nov 16, 2020 | In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible. | ||
| CVE-2020-24618 | Med | 0.42 | 6.5 | 0.02 | Aug 27, 2020 | In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access. | ||
| CVE-2020-15828 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions. | ||
| CVE-2020-15821 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft. | ||
| CVE-2020-11689 | Med | 0.42 | 6.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file. | ||
| CVE-2026-32745 | Med | 0.41 | 6.3 | 0.00 | Mar 13, 2026 | In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings | ||
| CVE-2024-56351 | Med | 0.41 | 6.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles | ||
| CVE-2024-52555 | Med | 0.41 | 6.3 | 0.00 | Nov 15, 2024 | In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script | ||
| CVE-2024-38506 | Med | 0.41 | 6.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows | ||
| CVE-2023-51655 | Med | 0.41 | 6.3 | 0.00 | Dec 21, 2023 | In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration | ||
| CVE-2026-49384 | Med | 0.40 | 6.1 | 0.00 | May 29, 2026 | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible | ||
| CVE-2026-49375 | Med | 0.40 | 6.1 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | ||
| CVE-2025-54527 | Med | 0.40 | 6.1 | 0.00 | Jul 28, 2025 | In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions | ||
| CVE-2025-43014 | Med | 0.40 | 6.1 | 0.00 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation | ||
| CVE-2024-31135 | Med | 0.40 | 6.1 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 open redirect was possible on the login page | ||
| CVE-2024-24941 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL | ||
| CVE-2022-48433 | Med | 0.40 | 6.1 | 0.01 | Mar 29, 2023 | In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server. | ||
| CVE-2022-48343 | Med | 0.40 | 5.4 | 0.59 | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process. | ||
| CVE-2022-46826 | Med | 0.40 | 6.2 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability. | ||
| CVE-2022-29811 | Med | 0.40 | 6.1 | 0.00 | Apr 28, 2022 | In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible. | ||
| CVE-2022-25261 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS. | ||
| CVE-2022-25259 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS. | ||
| CVE-2022-24338 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. | ||
| CVE-2022-24330 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. | ||
| CVE-2021-43181 | Med | 0.40 | 6.1 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, stored XSS is possible. | ||
| CVE-2021-43197 | Med | 0.40 | 6.1 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS. | ||
| CVE-2021-37542 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.3, XSS was possible. | ||
| CVE-2021-37541 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2021 | In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. | ||
| CVE-2021-31911 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. | ||
| CVE-2021-31904 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page. | ||
| CVE-2021-31903 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS. | ||
| CVE-2021-25773 | Med | 0.40 | 6.1 | 0.01 | Feb 3, 2021 | JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages. | ||
| CVE-2021-25757 | Med | 0.40 | 6.1 | 0.01 | Feb 3, 2021 | In JetBrains Hub before 2020.1.12629, an open redirect was possible. | ||
| CVE-2020-27627 | Med | 0.40 | 6.1 | 0.01 | Nov 16, 2020 | JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection. | ||
| CVE-2020-15831 | Med | 0.40 | 6.1 | 0.01 | Aug 8, 2020 | JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI. | ||
| CVE-2020-15830 | Med | 0.40 | 6.1 | 0.01 | Aug 8, 2020 | JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI. | ||
| CVE-2020-7913 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2020 | JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description. | ||
| CVE-2020-7911 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2020 | In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS. | ||
| CVE-2019-16171 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page. | ||
| CVE-2019-15037 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1. | ||
| CVE-2019-15041 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere. | ||
| CVE-2019-14961 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS. | ||
| CVE-2019-14953 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser. |
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.
- risk 0.42cvss 6.5epss 0.01
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
- risk 0.42cvss 6.5epss 0.01
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.
- risk 0.42cvss 6.5epss 0.01
In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.
- risk 0.42cvss 6.5epss 0.01
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
- risk 0.42cvss 6.5epss 0.02
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.
- risk 0.42cvss 6.5epss 0.01
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
- risk 0.41cvss 6.3epss 0.00
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
- risk 0.41cvss 6.3epss 0.00
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
- risk 0.41cvss 6.3epss 0.00
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script
- risk 0.41cvss 6.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows
- risk 0.41cvss 6.3epss 0.00
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
- risk 0.40cvss 6.1epss 0.00
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
- risk 0.40cvss 6.1epss 0.00
In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
- risk 0.40cvss 6.1epss 0.00
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
- risk 0.40cvss 6.1epss 0.00
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
- risk 0.40cvss 6.1epss 0.00
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
- risk 0.40cvss 6.1epss 0.00
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
- risk 0.40cvss 6.1epss 0.01
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
- risk 0.40cvss 5.4epss 0.59
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
- risk 0.40cvss 6.2epss 0.00
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
- risk 0.40cvss 6.1epss 0.00
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.3, XSS was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
- risk 0.40cvss 6.1epss 0.01
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
- risk 0.40cvss 6.1epss 0.01
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
Page 5 of 13