Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54538 | Med | 0.36 | 5.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command | ||
| CVE-2025-54537 | Med | 0.36 | 5.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots | ||
| CVE-2025-52876 | Med | 0.36 | 5.4 | 0.24 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible | ||
| CVE-2025-24457 | Med | 0.36 | 5.5 | 0.01 | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | ||
| CVE-2024-56354 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission | ||
| CVE-2024-56353 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies | ||
| CVE-2024-35301 | Med | 0.36 | 5.5 | 0.00 | May 16, 2024 | In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token | ||
| CVE-2024-31138 | Med | 0.36 | 4.6 | 0.75 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings | ||
| CVE-2022-48430 | Med | 0.36 | 5.5 | 0.00 | Mar 29, 2023 | In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview. | ||
| CVE-2022-46824 | Med | 0.36 | 5.6 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible. | ||
| CVE-2026-86483 | Med | 0.35 | 5.4 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible | ||
| CVE-2026-75053 | Med | 0.35 | 5.4 | 0.00 | Aug 17, 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | ||
| CVE-2025-68269 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH | ||
| CVE-2025-68268 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page | ||
| CVE-2025-68166 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab | ||
| CVE-2025-68165 | Med | 0.35 | 5.4 | 0.04 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup | ||
| CVE-2025-54536 | Med | 0.35 | 5.4 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint | ||
| CVE-2025-54528 | Med | 0.35 | 5.4 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow | ||
| CVE-2025-52875 | Med | 0.35 | 5.4 | 0.01 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible | ||
| CVE-2025-43016 | Med | 0.35 | 5.4 | 0.00 | Apr 25, 2025 | In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session | ||
| CVE-2024-50575 | Med | 0.35 | 5.4 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API | ||
| CVE-2024-48902 | Med | 0.35 | 5.4 | 0.00 | Oct 10, 2024 | In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API | ||
| CVE-2024-36366 | Med | 0.35 | 5.4 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations | ||
| CVE-2024-35302 | Med | 0.35 | 5.4 | 0.00 | May 16, 2024 | In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible | ||
| CVE-2024-24938 | Med | 0.35 | 5.3 | 0.01 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation | ||
| CVE-2023-39173 | Med | 0.35 | 5.4 | 0.00 | Jul 25, 2023 | In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access | ||
| CVE-2023-34225 | Med | 0.35 | 4.6 | 0.61 | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible | ||
| CVE-2023-34220 | Med | 0.35 | 4.6 | 0.61 | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible | ||
| CVE-2022-48428 | Med | 0.35 | 4.6 | 0.68 | Mar 27, 2023 | In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible | ||
| CVE-2022-48344 | Med | 0.35 | 5.4 | 0.00 | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process. | ||
| CVE-2022-36322 | Med | 0.35 | 5.4 | 0.01 | Jul 20, 2022 | In JetBrains TeamCity before 2022.04.2 build parameter injection was possible | ||
| CVE-2022-24347 | Med | 0.35 | 5.4 | 0.01 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon. | ||
| CVE-2022-24344 | Med | 0.35 | 5.4 | 0.01 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page. | ||
| CVE-2022-24339 | Med | 0.35 | 5.4 | 0.00 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS. | ||
| CVE-2022-24336 | Med | 0.35 | 5.3 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server. | ||
| CVE-2022-24334 | Med | 0.35 | 5.3 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server. | ||
| CVE-2022-24332 | Med | 0.35 | 5.3 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie. | ||
| CVE-2022-24329 | Med | 0.35 | 5.3 | 0.02 | Feb 25, 2022 | In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects. | ||
| CVE-2021-43201 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project. | ||
| CVE-2021-43199 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient. | ||
| CVE-2021-43198 | Med | 0.35 | 5.4 | 0.00 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, stored XSS is possible. | ||
| CVE-2021-43195 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing. | ||
| CVE-2021-43194 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, user enumeration was possible. | ||
| CVE-2021-43192 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. | ||
| CVE-2021-43191 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. | ||
| CVE-2021-43190 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. | ||
| CVE-2021-43187 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. | ||
| CVE-2021-43186 | Med | 0.35 | 5.4 | 0.01 | Nov 9, 2021 | JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. | ||
| CVE-2021-43184 | Med | 0.35 | 5.4 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. | ||
| CVE-2021-37552 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. |
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
- risk 0.36cvss 5.4epss 0.24
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
- risk 0.36cvss 5.5epss 0.01
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
- risk 0.36cvss 4.6epss 0.75
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
- risk 0.36cvss 5.5epss 0.00
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
- risk 0.36cvss 5.6epss 0.00
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
- risk 0.35cvss 5.4epss 0.00
In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
- risk 0.35cvss 5.4epss 0.00
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
- risk 0.35cvss 5.4epss 0.00
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
- risk 0.35cvss 5.4epss 0.04
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
- risk 0.35cvss 5.4epss 0.01
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
- risk 0.35cvss 5.4epss 0.00
In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session
- risk 0.35cvss 5.4epss 0.00
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
- risk 0.35cvss 5.4epss 0.00
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
- risk 0.35cvss 4.6epss 0.61
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
- risk 0.35cvss 4.6epss 0.61
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
- risk 0.35cvss 4.6epss 0.68
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
- risk 0.35cvss 5.4epss 0.01
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
- risk 0.35cvss 5.4epss 0.00
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.
- risk 0.35cvss 5.3epss 0.02
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
Page 7 of 13