← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
1Jetbrains
1Teamcity
Nov 21, 2024
Jun 29, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the...Show more
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Jun 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
1Jetbrains
1Youtrack
Jun 17, 2026
Jun 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
1Jetbrains
1Ktor
Jun 17, 2026
Jun 1, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
1Jetbrains
1Toolbox
Jun 17, 2026
Apr 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
1Jetbrains
1Hub
Jun 17, 2026
Apr 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
1Jetbrains
1Ktor
Jun 17, 2026
Apr 24, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible