Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hub CRITICAL 9.8
CVE-2026-25848

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

Fix: 2025.3.119807+
Fix from $2,300 2026-02-09
Pycharm MEDIUM 6.1
CVE-2026-25847

In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible

Fix: 2025.3.2+
Fix from $1,600 2026-02-09
Youtrack MEDIUM 6.5
CVE-2026-25846

In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

Fix: 2025.3.119033+
Fix from $1,600 2026-02-09
Teamcity MEDIUM 6.5
CVE-2025-68267

In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

Fix: 2025.11.1+
Fix from $1,600 2025-12-16
Teamcity MEDIUM 6.1
CVE-2025-68165

In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup

Fix: 2025.11+
Fix from $1,600 2025-12-16
Teamcity MEDIUM 6.1
CVE-2025-68166

In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab

Fix: 2025.11+
Fix from $1,600 2025-12-16
Teamcity MEDIUM 6.1
CVE-2025-68268

In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page

Fix: 2025.11.1+
Fix from $1,600 2025-12-16
Intellij Idea MEDIUM 5.4
CVE-2025-68269

In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH

Fix: 2025.3+
Fix from $1,600 2025-12-16
Teamcity HIGH 7.5
CVE-2025-67742

In JetBrains TeamCity before 2025.11 path traversal was possible via file upload

Fix: 2025.11+
Fix from $1,950 2025-12-11
Teamcity MEDIUM 5.4
CVE-2025-67741

In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute

Fix: 2025.11+
Fix from $1,600 2025-12-11
Teamcity MEDIUM 5.3
CVE-2025-67740

In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata

Fix: 2025.11+
Fix from $1,600 2025-12-11
Youtrack HIGH 7.5
CVE-2025-64685

In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

Fix: 2025.3.104432+
Fix from $1,950 2025-11-10
Resharper HIGH 7.8
CVE-2025-64456

In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation

Fix: 2025.2.4+
Fix from $1,950 2025-11-10
Hub HIGH 7.5
CVE-2025-64683

In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

Fix: 2025.3.104432+
Fix from $1,950 2025-11-10
Youtrack HIGH 7.5
CVE-2025-64684

In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

Fix: 2025.3.104432+
Fix from $1,950 2025-11-10
Dottrace HIGH 7.0
CVE-2025-64457

In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

Fix: 2025.2.5+
Fix from $1,950 2025-11-10
Junie CRITICAL 9.8
CVE-2025-59458

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243…

Fix: 243.284.50 / 251.284.50+
Fix from $2,300 2025-09-17
Teamcity HIGH 7.7
CVE-2025-59457

In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows

Fix: 2025.07.2+
Fix from $1,950 2025-09-17
Teamcity MEDIUM 5.5
CVE-2025-59456EPSS 13%

In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload

Fix: 2025.07.2+
Fix from $1,600 2025-09-17
Junie HIGH 7.5
CVE-2025-58335

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243…

Fix: 243.284.50 / 251.284.50+
Fix from $1,950 2025-08-28
Ide Services HIGH 8.8
CVE-2025-58334

In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

Fix: 2025.4.2.2164 / 2025.5.0.1086+
Fix from $1,950 2025-08-28
Teamcity MEDIUM 6.5
CVE-2025-57734

In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files

Fix: 2025.07.1+
Fix from $1,600 2025-08-20
Teamcity MEDIUM 6.3
CVE-2025-57732

In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

Fix: 2025.07.1+
Fix from $1,600 2025-08-20
Intellij Idea HIGH 7.5
CVE-2025-57727

In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference

Fix: 2025.2+
Fix from $1,950 2025-08-20
Intellij Idea HIGH 7.3
CVE-2025-57729

In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

Fix: 2025.2+
Fix from $1,950 2025-08-20
Intellij Idea MEDIUM 6.5
CVE-2025-57728

In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

Fix: 2025.2+
Fix from $1,600 2025-08-20
Youtrack MEDIUM 5.4
CVE-2025-57731

In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content

Fix: 2025.2.92387+
Fix from $1,600 2025-08-20
Teamcity MEDIUM 5.5
CVE-2025-54538

In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

Fix: 2025.07+
Fix from $1,600 2025-07-28
Teamcity HIGH 8.8
CVE-2025-54536

In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint

Fix: 2025.07+
Fix from $1,950 2025-07-28
Teamcity HIGH 7.5
CVE-2025-54535

In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

Fix: 2025.07+
Fix from $1,950 2025-07-28