← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Youtrack
Jun 1, 2026
May 29, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
1Jetbrains
1Youtrack
Jun 1, 2026
May 29, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
1Jetbrains
1Pycharm
Jun 1, 2026
May 29, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
1Jetbrains
1Intellij Idea
Jun 1, 2026
May 29, 2026
N/A· v4
3.3 LOW· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
1Jetbrains
1Intellij Idea
Jun 1, 2026
May 29, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
4.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
7.6 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
1Jetbrains
1Teamcity
Jun 2, 2026
May 29, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
1Jetbrains
1Youtrack
Jun 1, 2026
May 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
1Jetbrains
1Youtrack
Jun 1, 2026
May 29, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
1Jetbrains
1Youtrack
Jun 1, 2026
May 29, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
1Jetbrains
1Intellij Idea
Jun 1, 2026
May 29, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account