Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-63077 KEVEPSS 11% In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol Teamcity 2025.11.7 / 2026.1.3+ Fix from $2,3002026-07-27 CRITICAL 10.0 CVE-2026-65906 In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible Teamcity 2025.11.6 / 2026.1.2+ Fix from $2,3002026-07-23 HIGH 8.6 CVE-2026-65908 In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open Pycharm 2026.1.4+ Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-64815 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files Intellij Idea 2026.2+ Fix from $2,3002026-07-23 HIGH 8.6 CVE-2026-64814 In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session Intellij Idea 2026.2+ Fix from $1,9502026-07-23 CRITICAL 10.0 CVE-2026-64812 In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session Intellij Idea 2026.2+ Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-64813 In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session Intellij Idea 2026.2+ Fix from $2,3002026-07-23 HIGH 8.4 CVE-2026-64806 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter Webstorm 2026.2.0+ Fix from $1,9502026-07-23 HIGH 8.4 CVE-2026-64808 In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling Phpstorm 2026.2.0+ Fix from $1,9502026-07-23 HIGH 8.4 CVE-2026-64809 In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter Phpstorm 2026.2.0+ Fix from $1,9502026-07-23 HIGH 7.8 CVE-2026-64807 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration Webstorm 2026.2.0+ Fix from $1,9502026-07-23 HIGH 7.8 CVE-2026-64811 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration Intellij Idea 2026.2+ Fix from $1,9502026-07-23 MEDIUM 6.1 CVE-2026-64810 In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking Intellij Idea 2026.2+ Fix from $1,6002026-07-23 HIGH 8.4 CVE-2026-64804 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling Webstorm 2026.2.0+ Fix from $1,9502026-07-23 HIGH 8.4 CVE-2026-64805 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling Webstorm 2026.2.0+ Fix from $1,9502026-07-23 HIGH 7.8 CVE-2026-64802 In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration Goland 2026.2+ Fix from $1,9502026-07-23 HIGH 7.8 CVE-2026-64803 In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK Goland 2026.2+ Fix from $1,9502026-07-23 MEDIUM 5.7 CVE-2026-64800 In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default Goland 2026.2+ Fix from $1,6002026-07-23 CRITICAL 9.8 CVE-2026-62422 In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct… Youtrack 2024.2.148429 / 2024.3.148430+ Fix from $2,3002026-07-14 MEDIUM 6.1 CVE-2026-61492 In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible Youtrack 2026.2.17394+ Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-59792 In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible Intellij Idea 2026.1.4+ Fix from $2,3002026-07-10 HIGH 8.8 CVE-2026-59793 In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration Teamcity 2026.1.2+ Fix from $1,9502026-07-10 HIGH 8.1 CVE-2026-59796 In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks Teamcity 2026.1.2+ Fix from $1,9502026-07-10 MEDIUM 6.1 CVE-2026-59795 In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible Teamcity 2026.1.2+ Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-59794 In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data Teamcity 2026.1.2+ Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-57926 In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack Youtrack 2026.2.16593+ Fix from $2,3002026-06-26 HIGH 7.5 CVE-2026-57923 In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings Youtrack 2026.2.16593+ Fix from $1,9502026-06-26 MEDIUM 5.3 CVE-2026-57924 In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details Youtrack 2026.2.16593+ Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2026-57925 In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags Youtrack 2026.2.16593+ Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-57921 In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint Youtrack 2026.2.16593+ Fix from $1,9502026-06-26