Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion |
In JetBrains TeamCity before 2026.1
2025.11.5 authenticated users could expose server API to unauthorised access |
In JetBrains IntelliJ IDEA before 2024.3.7.1,
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server |
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file |
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass |
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings |
In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled |
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk |
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations |
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow |
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint |
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible |
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible |
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs |
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH |
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page |
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token |
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab |
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup |
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test |