← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
1Jetbrains
1Goland
Jun 17, 2026
Mar 25, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
1Jetbrains
1Ktor
Jun 17, 2026
Mar 12, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
1Jetbrains
1Runtime
Jun 17, 2026
Mar 12, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 11, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 11, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
1Jetbrains
4Dottrace
Etw Host ServiceResharper+1 more
Jun 17, 2026
Jan 28, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation v...Show more
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possibleShow less
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 21, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 21, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
1Jetbrains
1Youtrack
Jun 17, 2026
Jan 21, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
1Jetbrains
1Youtrack
Jun 17, 2026
Jan 21, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
1Jetbrains
1Hub
Jun 17, 2026
Jan 21, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page