Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-25848 In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible Hub 2025.3.119807+ Fix from $2,3002026-02-09 MEDIUM 6.1 CVE-2026-25847 In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible Pycharm 2025.3.2+ Fix from $1,6002026-02-09 MEDIUM 6.5 CVE-2026-25846 In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs Youtrack 2025.3.119033+ Fix from $1,6002026-02-09 MEDIUM 6.5 CVE-2025-68267 In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token Teamcity 2025.11.1+ Fix from $1,6002025-12-16 MEDIUM 6.1 CVE-2025-68165 In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup Teamcity 2025.11+ Fix from $1,6002025-12-16 MEDIUM 6.1 CVE-2025-68166 In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab Teamcity 2025.11+ Fix from $1,6002025-12-16 MEDIUM 6.1 CVE-2025-68268 In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page Teamcity 2025.11.1+ Fix from $1,6002025-12-16 MEDIUM 5.4 CVE-2025-68269 In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH Intellij Idea 2025.3+ Fix from $1,6002025-12-16 HIGH 7.5 CVE-2025-67742 In JetBrains TeamCity before 2025.11 path traversal was possible via file upload Teamcity 2025.11+ Fix from $1,9502025-12-11 MEDIUM 5.4 CVE-2025-67741 In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute Teamcity 2025.11+ Fix from $1,6002025-12-11 MEDIUM 5.3 CVE-2025-67740 In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata Teamcity 2025.11+ Fix from $1,6002025-12-11 HIGH 7.5 CVE-2025-64685 In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure Youtrack 2025.3.104432+ Fix from $1,9502025-11-10 HIGH 7.8 CVE-2025-64456 In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation Resharper 2025.2.4+ Fix from $1,9502025-11-10 HIGH 7.5 CVE-2025-64683 In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API Hub 2025.3.104432+ Fix from $1,9502025-11-10 HIGH 7.5 CVE-2025-64684 In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form Youtrack 2025.3.104432+ Fix from $1,9502025-11-10 HIGH 7.0 CVE-2025-64457 In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition Dottrace 2025.2.5+ Fix from $1,9502025-11-10 CRITICAL 9.8 CVE-2025-59458 In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243… Junie 243.284.50 / 251.284.50+ Fix from $2,3002025-09-17 HIGH 7.7 CVE-2025-59457 In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows Teamcity 2025.07.2+ Fix from $1,9502025-09-17 MEDIUM 5.5 CVE-2025-59456EPSS 13% In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload Teamcity 2025.07.2+ Fix from $1,6002025-09-17 HIGH 7.5 CVE-2025-58335 In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243… Junie 243.284.50 / 251.284.50+ Fix from $1,9502025-08-28 HIGH 8.8 CVE-2025-58334 In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves Ide Services 2025.4.2.2164 / 2025.5.0.1086+ Fix from $1,9502025-08-28 MEDIUM 6.5 CVE-2025-57734 In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files Teamcity 2025.07.1+ Fix from $1,6002025-08-20 MEDIUM 6.3 CVE-2025-57732 In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership Teamcity 2025.07.1+ Fix from $1,6002025-08-20 HIGH 7.5 CVE-2025-57727 In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference Intellij Idea 2025.2+ Fix from $1,9502025-08-20 HIGH 7.3 CVE-2025-57729 In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start Intellij Idea 2025.2+ Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-57728 In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files Intellij Idea 2025.2+ Fix from $1,6002025-08-20 MEDIUM 5.4 CVE-2025-57731 In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content Youtrack 2025.2.92387+ Fix from $1,6002025-08-20 MEDIUM 5.5 CVE-2025-54538 In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command Teamcity 2025.07+ Fix from $1,6002025-07-28 HIGH 8.8 CVE-2025-54536 In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint Teamcity 2025.07+ Fix from $1,9502025-07-28 HIGH 7.5 CVE-2025-54535 In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms Teamcity 2025.07+ Fix from $1,9502025-07-28