Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-25848
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Hub
2025.3.119807+
MEDIUM 6.1
CVE-2026-25847
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
Pycharm
2025.3.2+
MEDIUM 6.5
CVE-2026-25846
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Youtrack
2025.3.119033+
MEDIUM 6.5
CVE-2025-68267
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token
Teamcity
2025.11.1+
MEDIUM 6.1
CVE-2025-68165
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
Teamcity
2025.11+
MEDIUM 6.1
CVE-2025-68166
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
Teamcity
2025.11+
MEDIUM 6.1
CVE-2025-68268
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
Teamcity
2025.11.1+
MEDIUM 5.4
CVE-2025-68269
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
Intellij Idea
2025.3+
HIGH 7.5
CVE-2025-67742
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
Teamcity
2025.11+
MEDIUM 5.4
CVE-2025-67741
In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
Teamcity
2025.11+
MEDIUM 5.3
CVE-2025-67740
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
Teamcity
2025.11+
HIGH 7.5
CVE-2025-64685
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
Youtrack
2025.3.104432+
HIGH 7.8
CVE-2025-64456
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
Resharper
2025.2.4+
HIGH 7.5
CVE-2025-64683
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
Hub
2025.3.104432+
HIGH 7.5
CVE-2025-64684
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
Youtrack
2025.3.104432+
HIGH 7.0
CVE-2025-64457
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
Dottrace
2025.2.5+
CRITICAL 9.8
CVE-2025-59458
In JetBrains Junie before 252.284.66,
251.284.66,
243.284.66,
252.284.61,
251.284.61,
243.284.61,
252.284.50,
252.284.54,
251.284.54,
251.284.50,
243…
Junie
243.284.50 / 251.284.50+
HIGH 7.7
CVE-2025-59457
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
Teamcity
2025.07.2+
MEDIUM 5.5
CVE-2025-59456EPSS 13%
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
Teamcity
2025.07.2+
HIGH 7.5
CVE-2025-58335
In JetBrains Junie before 252.284.66,
251.284.66,
243.284.66,
252.284.61,
251.284.61,
243.284.61,
252.284.50,
252.284.54,
251.284.54,
251.284.50,
243…
Junie
243.284.50 / 251.284.50+
HIGH 8.8
CVE-2025-58334
In JetBrains IDE Services before 2025.5.0.1086,
2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves
Ide Services
2025.4.2.2164 / 2025.5.0.1086+
MEDIUM 6.5
CVE-2025-57734
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
Teamcity
2025.07.1+
MEDIUM 6.3
CVE-2025-57732
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
Teamcity
2025.07.1+
HIGH 7.5
CVE-2025-57727
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
Intellij Idea
2025.2+
HIGH 7.3
CVE-2025-57729
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
Intellij Idea
2025.2+
MEDIUM 6.5
CVE-2025-57728
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
Intellij Idea
2025.2+
MEDIUM 5.4
CVE-2025-57731
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
Youtrack
2025.2.92387+
MEDIUM 5.5
CVE-2025-54538
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
Teamcity
2025.07+
HIGH 8.8
CVE-2025-54536
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
Teamcity
2025.07+
HIGH 7.5
CVE-2025-54535
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
Teamcity
2025.07+