Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Teamcity CRITICAL 9.8
CVE-2026-63077 KEVEPSS 11%

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Fix: 2025.11.7 / 2026.1.3+
Fix from $2,300 2026-07-27
Teamcity CRITICAL 10.0
CVE-2026-65906

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

Fix: 2025.11.6 / 2026.1.2+
Fix from $2,300 2026-07-23
Pycharm HIGH 8.6
CVE-2026-65908

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

Fix: 2026.1.4+
Fix from $1,950 2026-07-23
Intellij Idea CRITICAL 9.8
CVE-2026-64815

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

Fix: 2026.2+
Fix from $2,300 2026-07-23
Intellij Idea HIGH 8.6
CVE-2026-64814

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

Fix: 2026.2+
Fix from $1,950 2026-07-23
Intellij Idea CRITICAL 10.0
CVE-2026-64812

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Fix: 2026.2+
Fix from $2,300 2026-07-23
Intellij Idea CRITICAL 10.0
CVE-2026-64813

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

Fix: 2026.2+
Fix from $2,300 2026-07-23
Webstorm HIGH 8.4
CVE-2026-64806

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Phpstorm HIGH 8.4
CVE-2026-64808

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Phpstorm HIGH 8.4
CVE-2026-64809

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Webstorm HIGH 7.8
CVE-2026-64807

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Intellij Idea HIGH 7.8
CVE-2026-64811

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

Fix: 2026.2+
Fix from $1,950 2026-07-23
Intellij Idea MEDIUM 6.1
CVE-2026-64810

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

Fix: 2026.2+
Fix from $1,600 2026-07-23
Webstorm HIGH 8.4
CVE-2026-64804

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Webstorm HIGH 8.4
CVE-2026-64805

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Goland HIGH 7.8
CVE-2026-64802

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

Fix: 2026.2+
Fix from $1,950 2026-07-23
Goland HIGH 7.8
CVE-2026-64803

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Fix: 2026.2+
Fix from $1,950 2026-07-23
Goland MEDIUM 5.7
CVE-2026-64800

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

Fix: 2026.2+
Fix from $1,600 2026-07-23
Youtrack CRITICAL 9.8
CVE-2026-62422

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $2,300 2026-07-14
Youtrack MEDIUM 6.1
CVE-2026-61492

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

Fix: 2026.2.17394+
Fix from $1,600 2026-07-10
Intellij Idea CRITICAL 9.8
CVE-2026-59792

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

Fix: 2026.1.4+
Fix from $2,300 2026-07-10
Teamcity HIGH 8.8
CVE-2026-59793

In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration

Fix: 2026.1.2+
Fix from $1,950 2026-07-10
Teamcity HIGH 8.1
CVE-2026-59796

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

Fix: 2026.1.2+
Fix from $1,950 2026-07-10
Teamcity MEDIUM 6.1
CVE-2026-59795

In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible

Fix: 2026.1.2+
Fix from $1,600 2026-07-10
Teamcity MEDIUM 5.4
CVE-2026-59794

In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data

Fix: 2026.1.2+
Fix from $1,600 2026-07-10
Youtrack CRITICAL 9.8
CVE-2026-57926

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Fix: 2026.2.16593+
Fix from $2,300 2026-06-26
Youtrack HIGH 7.5
CVE-2026-57923

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

Fix: 2026.2.16593+
Fix from $1,950 2026-06-26
Youtrack MEDIUM 5.3
CVE-2026-57924

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Fix: 2026.2.16593+
Fix from $1,600 2026-06-26
Youtrack MEDIUM 5.3
CVE-2026-57925

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

Fix: 2026.2.16593+
Fix from $1,600 2026-06-26
Youtrack HIGH 7.5
CVE-2026-57921

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

Fix: 2026.2.16593+
Fix from $1,950 2026-06-26