Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Filtered by product Intellij Idea
Total 76 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-75053 1 Jetbrains 1 Intellij Idea 2026-09-11 N/A 5.4 MEDIUM
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
CVE-2026-75054 1 Jetbrains 1 Intellij Idea 2026-09-11 N/A 6.3 MEDIUM
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
CVE-2026-75055 1 Jetbrains 1 Intellij Idea 2026-09-11 N/A 5.5 MEDIUM
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
CVE-2026-75056 1 Jetbrains 1 Intellij Idea 2026-09-11 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
CVE-2026-75057 1 Jetbrains 1 Intellij Idea 2026-09-11 N/A 6.2 MEDIUM
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
CVE-2026-75058 1 Jetbrains 1 Intellij Idea 2026-09-11 N/A 5.5 MEDIUM
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
CVE-2026-75052 1 Jetbrains 1 Intellij Idea 2026-09-01 N/A 3.6 LOW
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
CVE-2026-64815 1 Jetbrains 1 Intellij Idea 2026-07-28 N/A 8.1 HIGH
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
CVE-2026-64814 1 Jetbrains 1 Intellij Idea 2026-07-28 N/A 8.6 HIGH
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
CVE-2026-64813 1 Jetbrains 1 Intellij Idea 2026-07-28 N/A 10.0 CRITICAL
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
CVE-2026-64812 1 Jetbrains 1 Intellij Idea 2026-07-28 N/A 10.0 CRITICAL
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
CVE-2026-64811 1 Jetbrains 1 Intellij Idea 2026-07-28 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
CVE-2026-64810 1 Jetbrains 1 Intellij Idea 2026-07-28 N/A 4.3 MEDIUM
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
CVE-2026-49383 1 Jetbrains 1 Intellij Idea 2026-07-22 N/A 3.3 LOW
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
CVE-2026-49366 1 Jetbrains 1 Intellij Idea 2026-07-22 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-49367 1 Jetbrains 1 Intellij Idea 2026-07-22 N/A 8.0 HIGH
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-49382 1 Jetbrains 1 Intellij Idea 2026-07-22 N/A 4.5 MEDIUM
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
CVE-2026-59792 1 Jetbrains 1 Intellij Idea 2026-07-14 N/A 9.6 CRITICAL
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
CVE-2026-41882 1 Jetbrains 1 Intellij Idea 2026-06-17 N/A 7.4 HIGH
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
CVE-2025-68269 1 Jetbrains 1 Intellij Idea 2026-06-17 N/A 5.4 MEDIUM
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH