Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Youtrack MEDIUM 5.3
CVE-2026-57922

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

Fix: 2026.2.16593+
Fix from $1,600 2026-06-26
Kotlin CRITICAL 9.8
CVE-2026-53914

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

Fix: 2.4.20+
Fix from $2,300 2026-06-26
Hub CRITICAL 9.8
CVE-2026-56141

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable rest…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $2,300 2026-06-19
Goland HIGH 8.8
CVE-2026-53915

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

Fix: 2026.1.3+
Fix from $1,950 2026-06-19
Hub HIGH 8.8
CVE-2026-56142

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching aut…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $1,950 2026-06-19
Hub CRITICAL 9.8
CVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct data…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $2,300 2026-06-19
Intellij Idea HIGH 7.8
CVE-2026-49382

In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin

Fix: 2026.1+
Fix from $1,950 2026-05-29
Youtrack MEDIUM 6.5
CVE-2026-49385

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

Fix: 2026.1.13570+
Fix from $1,600 2026-05-29
Youtrack MEDIUM 6.5
CVE-2026-49386

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

Fix: 2026.1.13570+
Fix from $1,600 2026-05-29
Pycharm MEDIUM 6.1
CVE-2026-49384

In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

Fix: 2025.3.4+
Fix from $1,600 2026-05-29
Teamcity HIGH 8.8
CVE-2026-49373EPSS 13%

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

Fix: 2026.1+
Fix from $1,950 2026-05-29
Teamcity HIGH 7.6
CVE-2026-49374

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

Fix: 2026.1+
Fix from $1,950 2026-05-29
Teamcity HIGH 7.5
CVE-2026-49372

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

Fix: 2025.11.5+
Fix from $1,950 2026-05-29
Teamcity MEDIUM 6.5
CVE-2026-49376

In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

Fix: 2026.1+
Fix from $1,600 2026-05-29
Teamcity MEDIUM 6.5
CVE-2026-49379

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

Fix: 2026.1+
Fix from $1,600 2026-05-29
Teamcity MEDIUM 6.1
CVE-2026-49375

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

Fix: 2025.11.5+
Fix from $1,600 2026-05-29
Teamcity MEDIUM 6.1
CVE-2026-49380

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

Fix: 2026.1+
Fix from $1,600 2026-05-29
Intellij Idea HIGH 8.8
CVE-2026-49367

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

Fix: 2026.1.1+
Fix from $1,950 2026-05-29
Teamcity HIGH 8.2
CVE-2026-49371

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

Fix: 2026.1.1+
Fix from $1,950 2026-05-29
Intellij Idea HIGH 7.8
CVE-2026-49366

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

Fix: 2026.1.1+
Fix from $1,950 2026-05-29
Youtrack HIGH 7.5
CVE-2026-49370

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Fix: 2026.1.13162+
Fix from $1,950 2026-05-29
Youtrack MEDIUM 5.4
CVE-2026-49368

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

Fix: 2026.1.13162+
Fix from $1,600 2026-05-29
Teamcity HIGH 7.5
CVE-2026-44413

In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access

Fix: 2025.11.5+
Fix from $1,950 2026-05-11
Intellij Idea HIGH 7.5
CVE-2026-41882

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-i…

Mitigation only
Fix from $1,950 2026-04-30
Junie CRITICAL 9.8
CVE-2026-41153

In JetBrains Junie before 252.549.29 command execution was possible via malicious project file

Fix: 252.549.29+
Fix from $2,300 2026-04-17
Youtrack HIGH 7.2
CVE-2026-33392

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

Fix: 2025.3.131383+
Fix from $1,950 2026-04-17
Datalore MEDIUM 5.7
CVE-2026-32745

In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings

Fix: 2026.1+
Fix from $1,600 2026-03-13
Hub MEDIUM 6.8
CVE-2026-32229

In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled

Fix: 2025.3.128064+
Fix from $1,600 2026-03-11
Teamcity MEDIUM 6.1
CVE-2026-28194

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

Fix: 2025.11.3+
Fix from $1,600 2026-02-25
Youtrack MEDIUM 5.3
CVE-2026-28193

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

Fix: 2025.3.121962+
Fix from $1,600 2026-02-25