← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
May 12, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
1Jetbrains
1Pycharm
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.7 HIGH· v3
4.4 MEDIUM· v2
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
1Jetbrains
1Pycharm
Jun 17, 2026
Apr 28, 2022
N/A· v4
3.5 LOW· v3
3.3 LOW· v2
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.7 HIGH· v3
4.4 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.7 HIGH· v3
4.4 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
1Jetbrains
1Hub
Jun 17, 2026
Apr 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
1Jetbrains
1Ktor
Jun 17, 2026
Apr 11, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 5, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
1Jetbrains
1Youtrack
Jun 17, 2026
Apr 5, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
1Jetbrains
1Youtrack
Jun 17, 2026
Apr 5, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
1Jetbrains
1Youtrack
Jun 17, 2026
Apr 5, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.