← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Intellij Idea
Jun 1, 2026
May 29, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
1Jetbrains
1Teamcity
May 12, 2026
May 11, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
1Jetbrains
1Intellij Idea
May 5, 2026
Apr 30, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
1Jetbrains
1Junie
Apr 27, 2026
Apr 17, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
1Jetbrains
1Youtrack
Apr 20, 2026
Apr 17, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
1Jetbrains
1Datalore
Apr 2, 2026
Mar 13, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
1Jetbrains
1Hub
Apr 2, 2026
Mar 11, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled
1Jetbrains
1Teamcity
Feb 25, 2026
Feb 25, 2026
N/A· v4
2.3 LOW· v3
N/A· v2
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
1Jetbrains
1Teamcity
Feb 25, 2026
Feb 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
1Jetbrains
1Teamcity
Feb 25, 2026
Feb 25, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
1Jetbrains
1Youtrack
Feb 26, 2026
Feb 25, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
1Jetbrains
1Hub
Feb 18, 2026
Feb 9, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
1Jetbrains
1Pycharm
Feb 18, 2026
Feb 9, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
1Jetbrains
1Youtrack
Feb 18, 2026
Feb 9, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
1Jetbrains
1Intellij Idea
Dec 23, 2025
Dec 16, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
1Jetbrains
1Teamcity
Dec 18, 2025
Dec 16, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
1Jetbrains
1Teamcity
Dec 18, 2025
Dec 16, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token
1Jetbrains
1Teamcity
Dec 18, 2025
Dec 16, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
1Jetbrains
1Teamcity
Dec 18, 2025
Dec 16, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
1Jetbrains
1Teamcity
Dec 18, 2025
Dec 16, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test