Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38505 | Med | 0.34 | 5.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site | ||
| CVE-2024-36375 | Med | 0.34 | 5.3 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed | ||
| CVE-2024-28228 | Med | 0.34 | 5.3 | 0.00 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | ||
| CVE-2024-24943 | Med | 0.34 | 5.3 | 0.00 | Feb 6, 2024 | In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image | ||
| CVE-2023-41249 | Med | 0.34 | 4.6 | 0.56 | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | ||
| CVE-2023-39261 | Med | 0.34 | 5.2 | 0.00 | Jul 26, 2023 | In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions | ||
| CVE-2023-34228 | Med | 0.34 | 5.3 | 0.00 | May 31, 2023 | In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions | ||
| CVE-2023-34227 | Med | 0.34 | 5.3 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks | ||
| CVE-2022-48481 | Med | 0.34 | 5.2 | 0.00 | Apr 28, 2023 | In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible | ||
| CVE-2022-48432 | Med | 0.34 | 5.2 | 0.00 | Mar 29, 2023 | In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed. | ||
| CVE-2022-48342 | Med | 0.34 | 5.2 | 0.00 | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents. | ||
| CVE-2022-46828 | Med | 0.34 | 5.2 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. | ||
| CVE-2021-37546 | Med | 0.34 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. | ||
| CVE-2021-25763 | Med | 0.34 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default. | ||
| CVE-2021-25761 | Med | 0.34 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible. | ||
| CVE-2019-18361 | Med | 0.34 | 5.3 | 0.00 | Oct 31, 2019 | JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution. | ||
| CVE-2024-39879 | Med | 0.33 | 5.0 | 0.00 | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings | ||
| CVE-2022-47896 | Med | 0.33 | 5.0 | 0.00 | Dec 22, 2022 | In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. | ||
| CVE-2019-19703 | Med | 0.33 | 6.1 | 0.01 | Dec 10, 2019 | In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location. | ||
| CVE-2025-52877 | Med | 0.32 | 4.8 | 0.24 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible | ||
| CVE-2025-46433 | Med | 0.32 | 4.9 | 0.01 | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible | ||
| CVE-2025-31140 | Med | 0.32 | 4.6 | 0.28 | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page | ||
| CVE-2024-47948 | Med | 0.32 | 4.9 | 0.01 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups | ||
| CVE-2020-11938 | Med | 0.32 | 4.9 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2. | ||
| CVE-2019-15035 | Med | 0.32 | 4.9 | 0.01 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1. | ||
| CVE-2026-68762 | Med | 0.31 | 5.9 | 0.00 | Aug 17, 2026 | In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible | ||
| CVE-2025-57727 | Med | 0.31 | 4.7 | 0.00 | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference | ||
| CVE-2025-54534 | Med | 0.31 | 4.8 | 0.01 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page | ||
| CVE-2025-52879 | Med | 0.31 | 4.8 | 0.01 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible | ||
| CVE-2025-47853 | Med | 0.31 | 4.8 | 0.01 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible | ||
| CVE-2025-47852 | Med | 0.31 | 4.8 | 0.01 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible | ||
| CVE-2025-47851 | Med | 0.31 | 4.8 | 0.03 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible | ||
| CVE-2023-34224 | Med | 0.31 | 4.8 | 0.00 | May 31, 2023 | In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible | ||
| CVE-2022-47895 | Med | 0.31 | 4.7 | 0.00 | Dec 22, 2022 | In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files. | ||
| CVE-2026-86484 | Med | 0.30 | 4.6 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | ||
| CVE-2025-67741 | Med | 0.30 | 4.6 | 0.00 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute | ||
| CVE-2025-26493 | Med | 0.30 | 4.6 | 0.00 | Feb 11, 2025 | In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab | ||
| CVE-2025-24459 | Med | 0.30 | 4.6 | 0.03 | Jan 21, 2025 | In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page | ||
| CVE-2024-56355 | Med | 0.30 | 4.6 | 0.01 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS | ||
| CVE-2024-56352 | Med | 0.30 | 4.6 | 0.01 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page | ||
| CVE-2024-50582 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements | ||
| CVE-2024-50581 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag | ||
| CVE-2024-50580 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule | ||
| CVE-2024-50579 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible | ||
| CVE-2024-50578 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page | ||
| CVE-2024-50577 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings | ||
| CVE-2024-50576 | Med | 0.30 | 4.6 | 0.00 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest | ||
| CVE-2024-43810 | Med | 0.30 | 4.6 | 0.00 | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin | ||
| CVE-2024-43807 | Med | 0.30 | 4.6 | 0.00 | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page | ||
| CVE-2024-41825 | Med | 0.30 | 4.6 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab |
- risk 0.34cvss 5.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
- risk 0.34cvss 5.3epss 0.00
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
- risk 0.34cvss 5.3epss 0.00
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
- risk 0.34cvss 4.6epss 0.56
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
- risk 0.34cvss 5.3epss 0.01
In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks
- risk 0.34cvss 5.2epss 0.00
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
- risk 0.34cvss 5.2epss 0.00
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
- risk 0.34cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
- risk 0.34cvss 5.3epss 0.01
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
- risk 0.34cvss 5.3epss 0.01
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
- risk 0.34cvss 5.3epss 0.00
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.
- risk 0.33cvss 5.0epss 0.00
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
- risk 0.33cvss 5.0epss 0.00
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
- risk 0.33cvss 6.1epss 0.01
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
- risk 0.32cvss 4.8epss 0.24
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
- risk 0.32cvss 4.9epss 0.01
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
- risk 0.32cvss 4.6epss 0.28
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
- risk 0.32cvss 4.9epss 0.01
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
- risk 0.32cvss 4.9epss 0.01
In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
- risk 0.31cvss 5.9epss 0.00
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
- risk 0.31cvss 4.7epss 0.00
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
- risk 0.31cvss 4.8epss 0.01
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
- risk 0.31cvss 4.8epss 0.01
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
- risk 0.31cvss 4.8epss 0.01
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
- risk 0.31cvss 4.8epss 0.01
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
- risk 0.31cvss 4.8epss 0.03
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
- risk 0.31cvss 4.8epss 0.00
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
- risk 0.31cvss 4.7epss 0.00
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
- risk 0.30cvss 4.6epss 0.03
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
- risk 0.30cvss 4.6epss 0.00
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
- risk 0.30cvss 4.6epss 0.00
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
Page 9 of 13