Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14952 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2019 | JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles. | ||
| CVE-2019-15848 | Med | 0.40 | 6.1 | 0.01 | Sep 5, 2019 | JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user. | ||
| CVE-2019-12844 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3. | ||
| CVE-2019-12843 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3. | ||
| CVE-2019-12842 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2. | ||
| CVE-2026-41153 | Med | 0.38 | 5.8 | 0.00 | Apr 17, 2026 | In JetBrains Junie before 252.549.29 command execution was possible via malicious project file | ||
| CVE-2025-54535 | Med | 0.38 | 5.8 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms | ||
| CVE-2024-56356 | Med | 0.38 | 5.9 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | ||
| CVE-2024-36378 | Med | 0.38 | 5.9 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens | ||
| CVE-2024-35299 | Med | 0.38 | 5.9 | 0.00 | May 16, 2024 | In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation | ||
| CVE-2024-31139 | Med | 0.38 | 5.9 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector | ||
| CVE-2024-28174 | Med | 0.38 | 5.8 | 0.00 | Mar 6, 2024 | In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly | ||
| CVE-2019-14959 | Med | 0.38 | 5.9 | 0.01 | Oct 2, 2019 | JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection. | ||
| CVE-2019-14954 | Med | 0.38 | 5.9 | 0.01 | Oct 1, 2019 | JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection. | ||
| CVE-2026-53914 | Med | 0.37 | 6.7 | 0.00 | Jun 26, 2026 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata | ||
| CVE-2025-59456 | Med | 0.37 | 5.5 | 0.12 | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload | ||
| CVE-2024-24942 | Med | 0.37 | 5.3 | 0.32 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | ||
| CVE-2022-28648 | Med | 0.37 | 5.7 | 0.01 | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered | ||
| CVE-2025-58335 | Med | 0.36 | 5.5 | 0.00 | Aug 28, 2025 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function | ||
| CVE-2025-57733 | Med | 0.36 | 5.5 | 0.00 | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content | ||
| CVE-2025-54538 | Med | 0.36 | 5.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command | ||
| CVE-2025-54537 | Med | 0.36 | 5.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots | ||
| CVE-2025-52876 | Med | 0.36 | 5.4 | 0.17 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible | ||
| CVE-2025-24457 | Med | 0.36 | 5.5 | 0.01 | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | ||
| CVE-2024-56354 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission | ||
| CVE-2024-56353 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies | ||
| CVE-2024-35301 | Med | 0.36 | 5.5 | 0.00 | May 16, 2024 | In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token | ||
| CVE-2024-31138 | Med | 0.36 | 4.6 | 0.74 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings | ||
| CVE-2022-48430 | Med | 0.36 | 5.5 | 0.00 | Mar 29, 2023 | In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview. | ||
| CVE-2022-46824 | Med | 0.36 | 5.6 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible. | ||
| CVE-2025-68269 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH | ||
| CVE-2025-68268 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page | ||
| CVE-2025-68166 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab | ||
| CVE-2025-68165 | Med | 0.35 | 5.4 | 0.04 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup | ||
| CVE-2025-54536 | Med | 0.35 | 5.4 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint | ||
| CVE-2025-54528 | Med | 0.35 | 5.4 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow | ||
| CVE-2025-52875 | Med | 0.35 | 5.4 | 0.01 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible | ||
| CVE-2025-43016 | Med | 0.35 | 5.4 | 0.00 | Apr 25, 2025 | In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session | ||
| CVE-2024-50575 | Med | 0.35 | 5.4 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API | ||
| CVE-2024-48902 | Med | 0.35 | 5.4 | 0.00 | Oct 10, 2024 | In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API | ||
| CVE-2024-36366 | Med | 0.35 | 5.4 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations | ||
| CVE-2024-35302 | Med | 0.35 | 5.4 | 0.00 | May 16, 2024 | In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible | ||
| CVE-2024-24938 | Med | 0.35 | 5.3 | 0.01 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation | ||
| CVE-2023-39173 | Med | 0.35 | 5.4 | 0.00 | Jul 25, 2023 | In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access | ||
| CVE-2023-34225 | Med | 0.35 | 4.6 | 0.61 | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible | ||
| CVE-2023-34220 | Med | 0.35 | 4.6 | 0.61 | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible | ||
| CVE-2022-48428 | Med | 0.35 | 4.6 | 0.68 | Mar 27, 2023 | In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible | ||
| CVE-2022-48344 | Med | 0.35 | 5.4 | 0.00 | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process. | ||
| CVE-2022-36322 | Med | 0.35 | 5.4 | 0.01 | Jul 20, 2022 | In JetBrains TeamCity before 2022.04.2 build parameter injection was possible | ||
| CVE-2022-24347 | Med | 0.35 | 5.4 | 0.01 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon. |
- risk 0.40cvss 6.1epss 0.01
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
- risk 0.40cvss 6.1epss 0.01
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
- risk 0.40cvss 6.1epss 0.01
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
- risk 0.40cvss 6.1epss 0.01
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
- risk 0.38cvss 5.8epss 0.00
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
- risk 0.38cvss 5.8epss 0.00
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
- risk 0.38cvss 5.9epss 0.00
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
- risk 0.38cvss 5.8epss 0.00
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
- risk 0.38cvss 5.9epss 0.01
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
- risk 0.38cvss 5.9epss 0.01
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
- risk 0.37cvss 6.7epss 0.00
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
- risk 0.37cvss 5.5epss 0.12
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
- risk 0.37cvss 5.3epss 0.32
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
- risk 0.37cvss 5.7epss 0.01
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
- risk 0.36cvss 5.5epss 0.00
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
- risk 0.36cvss 5.4epss 0.17
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
- risk 0.36cvss 5.5epss 0.01
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
- risk 0.36cvss 4.6epss 0.74
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
- risk 0.36cvss 5.5epss 0.00
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
- risk 0.36cvss 5.6epss 0.00
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
- risk 0.35cvss 5.4epss 0.00
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
- risk 0.35cvss 5.4epss 0.04
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
- risk 0.35cvss 5.4epss 0.01
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
- risk 0.35cvss 5.4epss 0.00
In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session
- risk 0.35cvss 5.4epss 0.00
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
- risk 0.35cvss 5.4epss 0.00
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
- risk 0.35cvss 4.6epss 0.61
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
- risk 0.35cvss 4.6epss 0.61
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
- risk 0.35cvss 4.6epss 0.68
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
- risk 0.35cvss 5.4epss 0.01
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
Page 6 of 13