Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-57922 In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible Youtrack 2026.2.16593+ Fix from $1,6002026-06-26 CRITICAL 9.8 CVE-2026-53914 In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata Kotlin 2.4.20+ Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-56141 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable rest… Hub 2024.2.148429 / 2024.3.148430+ Fix from $2,3002026-06-19 HIGH 8.8 CVE-2026-53915 In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration Goland 2026.1.3+ Fix from $1,9502026-06-19 HIGH 8.8 CVE-2026-56142 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching aut… Hub 2024.2.148429 / 2024.3.148430+ Fix from $1,9502026-06-19 CRITICAL 9.8 CVE-2026-50242 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct data… Hub 2024.2.148429 / 2024.3.148430+ Fix from $2,3002026-06-19 HIGH 7.8 CVE-2026-49382 In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin Intellij Idea 2026.1+ Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-49385 In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts Youtrack 2026.1.13570+ Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-49386 In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas Youtrack 2026.1.13570+ Fix from $1,6002026-05-29 MEDIUM 6.1 CVE-2026-49384 In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible Pycharm 2025.3.4+ Fix from $1,6002026-05-29 HIGH 8.8 CVE-2026-49373EPSS 13% In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings Teamcity 2026.1+ Fix from $1,9502026-05-29 HIGH 7.6 CVE-2026-49374 In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters Teamcity 2026.1+ Fix from $1,9502026-05-29 HIGH 7.5 CVE-2026-49372 In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible Teamcity 2025.11.5+ Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-49376 In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin Teamcity 2026.1+ Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-49379 In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names Teamcity 2026.1+ Fix from $1,6002026-05-29 MEDIUM 6.1 CVE-2026-49375 In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page Teamcity 2025.11.5+ Fix from $1,6002026-05-29 MEDIUM 6.1 CVE-2026-49380 In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible Teamcity 2026.1+ Fix from $1,6002026-05-29 HIGH 8.8 CVE-2026-49367 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account Intellij Idea 2026.1.1+ Fix from $1,9502026-05-29 HIGH 8.2 CVE-2026-49371 In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible Teamcity 2026.1.1+ Fix from $1,9502026-05-29 HIGH 7.8 CVE-2026-49366 In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion Intellij Idea 2026.1.1+ Fix from $1,9502026-05-29 HIGH 7.5 CVE-2026-49370 In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests Youtrack 2026.1.13162+ Fix from $1,9502026-05-29 MEDIUM 5.4 CVE-2026-49368 In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible Youtrack 2026.1.13162+ Fix from $1,6002026-05-29 HIGH 7.5 CVE-2026-44413 In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access Teamcity 2025.11.5+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-41882 In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-i… Intellij Idea Mitigation only Fix from $1,9502026-04-30 CRITICAL 9.8 CVE-2026-41153 In JetBrains Junie before 252.549.29 command execution was possible via malicious project file Junie 252.549.29+ Fix from $2,3002026-04-17 HIGH 7.2 CVE-2026-33392 In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass Youtrack 2025.3.131383+ Fix from $1,9502026-04-17 MEDIUM 5.7 CVE-2026-32745 In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings Datalore 2026.1+ Fix from $1,6002026-03-13 MEDIUM 6.8 CVE-2026-32229 In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled Hub 2025.3.128064+ Fix from $1,6002026-03-11 MEDIUM 6.1 CVE-2026-28194 In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow Teamcity 2025.11.3+ Fix from $1,6002026-02-25 MEDIUM 5.3 CVE-2026-28193 In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint Youtrack 2025.3.121962+ Fix from $1,6002026-02-25