← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Dec 18, 2025
Dec 16, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
1Jetbrains
1Teamcity
Dec 18, 2025
Dec 16, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
1Jetbrains
1Teamcity
Dec 15, 2025
Dec 11, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
1Jetbrains
1Teamcity
Dec 15, 2025
Dec 11, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
1Jetbrains
1Teamcity
Dec 15, 2025
Dec 11, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
1Jetbrains
1Teamcity
Dec 23, 2025
Dec 11, 2025
N/A· v4
3.1 LOW· v3
N/A· v2
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
1Jetbrains
1Youtrack
Dec 11, 2025
Nov 11, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
1Jetbrains
1Youtrack
Nov 21, 2025
Nov 10, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
1Jetbrains
1Youtrack
Nov 21, 2025
Nov 10, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
1Jetbrains
1Hub
Nov 21, 2025
Nov 10, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
1Jetbrains
1Hub
Nov 20, 2025
Nov 10, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
1Jetbrains
1Hub
Nov 20, 2025
Nov 10, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
1Jetbrains
3Dottrace
ResharperRider
Jan 12, 2026
Nov 10, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
1Jetbrains
1Resharper
Nov 20, 2025
Nov 10, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
1Jetbrains
1Junie
Jan 20, 2026
Sep 17, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command...Show more
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validationShow less
1Jetbrains
1Teamcity
Sep 22, 2025
Sep 17, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
1Jetbrains
1Teamcity
Sep 22, 2025
Sep 17, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
1Jetbrains
1Teamcity
Sep 22, 2025
Sep 17, 2025
N/A· v4
4.2 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
1Jetbrains
1Junie
Jan 20, 2026
Aug 28, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_proj...Show more
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project functionShow less
1Jetbrains
1Ide Services
Oct 14, 2025
Aug 28, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves