← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
1Jetbrains
1Webstorm
Jun 17, 2026
Nov 15, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 28, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality