← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 20, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
1Jetbrains
1Youtrack
Jun 17, 2026
Aug 20, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
1Jetbrains
1Intellij Idea
Jun 17, 2026
Aug 20, 2025
N/A· v4
4.6 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
1Jetbrains
1Intellij Idea
Jun 17, 2026
Aug 20, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
1Jetbrains
1Intellij Idea
Jun 17, 2026
Aug 20, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
1Jetbrains
1Intellij Idea
Jun 17, 2026
Aug 20, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
9.4 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 28, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
1Jetbrains
1Youtrack
Jun 17, 2026
Jul 28, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
1Jetbrains
1Youtrack
Jun 17, 2026
Jul 15, 2025
N/A· v4
7.6 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Jun 23, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible