← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Jetbrains
Oracle
4Communications Cloud Native Core Network Slice Selection Function
Communications Cloud Native Core PolicyCommunications Cloud Native Core Service Communication Proxy+1 more
Jun 17, 2026
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
1Jetbrains
1Youtrack
Jun 17, 2026
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 16, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
1Jetbrains
1Ideavim
Jun 17, 2026
Nov 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
1Jetbrains
1Ktor
Jun 17, 2026
Nov 16, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 16, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
1Jetbrains
1Toolbox
Jun 17, 2026
Nov 16, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
1Jetbrains
1Toolbox
Jun 17, 2026
Nov 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 16, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 19, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
1Jetbrains
1Youtrack
Jun 17, 2026
Aug 27, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.