← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Hub
Jun 17, 2026
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services
1Jetbrains
1Ktor
Jun 17, 2026
Oct 17, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 10, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 8, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 8, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
1Jetbrains
1Youtrack
Jun 17, 2026
Sep 19, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
1Jetbrains
1Youtrack
Jun 17, 2026
Sep 19, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
1Jetbrains
1Youtrack
Jun 17, 2026
Sep 19, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
1Jetbrains
1Intellij Idea
Jun 17, 2026
Sep 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 16, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 16, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 16, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 22, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time