Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 618 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-59795 1 Jetbrains 1 Teamcity 2026-07-13 N/A 8.1 HIGH
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
CVE-2026-59791 1 Jetbrains 1 Youtrack 2026-07-10 N/A 3.5 LOW
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
CVE-2026-61492 1 Jetbrains 1 Youtrack 2026-07-10 N/A 3.5 LOW
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
CVE-2026-59794 1 Jetbrains 1 Teamcity 2026-07-10 N/A 7.3 HIGH
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
CVE-2026-53914 1 Jetbrains 1 Kotlin 2026-06-27 N/A 6.7 MEDIUM
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
CVE-2026-57921 1 Jetbrains 1 Youtrack 2026-06-27 N/A 4.3 MEDIUM
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
CVE-2026-57922 1 Jetbrains 1 Youtrack 2026-06-27 N/A 3.1 LOW
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
CVE-2026-57923 1 Jetbrains 1 Youtrack 2026-06-27 N/A 5.3 MEDIUM
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
CVE-2026-57924 1 Jetbrains 1 Youtrack 2026-06-27 N/A 4.3 MEDIUM
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
CVE-2026-57925 1 Jetbrains 1 Youtrack 2026-06-27 N/A 4.3 MEDIUM
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
CVE-2026-57926 1 Jetbrains 1 Youtrack 2026-06-27 N/A 2.6 LOW
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVE-2026-50242 1 Jetbrains 1 Hub 2026-06-26 N/A 10.0 CRITICAL
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
CVE-2026-53915 1 Jetbrains 1 Goland 2026-06-26 N/A 7.1 HIGH
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
CVE-2026-56141 1 Jetbrains 1 Hub 2026-06-26 N/A 9.8 CRITICAL
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
CVE-2026-56142 1 Jetbrains 1 Hub 2026-06-26 N/A 9.9 CRITICAL
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
CVE-2026-44413 1 Jetbrains 1 Teamcity 2026-06-17 N/A 8.2 HIGH
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-41882 1 Jetbrains 1 Intellij Idea 2026-06-17 N/A 7.4 HIGH
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
CVE-2026-41153 1 Jetbrains 1 Junie 2026-06-17 N/A 5.8 MEDIUM
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
CVE-2026-33392 1 Jetbrains 1 Youtrack 2026-06-17 N/A 7.2 HIGH
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
CVE-2026-32745 1 Jetbrains 1 Datalore 2026-06-17 N/A 6.3 MEDIUM
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings