Skip to main content

Vendor archive

jetbrains CVEs

Beta · best-effort

599 CVEs tagged to vendor jetbrains49 Critical, 138 High, 347 Medium, 65 Low, 0 Unrated.

CVE-2026-49371

Published May 29, 2026

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49370

Published May 29, 2026

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49369

Published May 29, 2026

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49368

Published May 29, 2026

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49367

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49366

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44413

Published May 11, 2026

In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access

CVSS 8.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-41882

Published Apr 30, 2026

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41153

Published Apr 17, 2026

In JetBrains Junie before 252.549.29 command execution was possible via malicious project file

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33392

Published Apr 17, 2026

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32745

Published Mar 13, 2026

In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32229

Published Mar 11, 2026

In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28196

Published Feb 25, 2026

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28195

Published Feb 25, 2026

In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28194

Published Feb 25, 2026

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28193

Published Feb 25, 2026

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25848

Published Feb 9, 2026

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25847

Published Feb 9, 2026

In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25846

Published Feb 9, 2026

In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68269

Published Dec 16, 2025

In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68268

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68267

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68166

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68164

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort
Showing 51-75 of 599 CVEsPage 3 of 24