Skip to main content

Vendor archive

jetbrains CVEs

Beta · best-effort

601 CVEs tagged to vendor jetbrains50 Critical, 139 High, 347 Medium, 65 Low, 0 Unrated.

CVE-2025-68164

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-68163

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-68162

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-67741

Published Dec 11, 2025

In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67740

Published Dec 11, 2025

In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-67739

Published Dec 11, 2025

In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64773

Published Nov 11, 2025

In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64685

Published Nov 10, 2025

In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64684

Published Nov 10, 2025

In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64683

Published Nov 10, 2025

In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64682

Published Nov 10, 2025

In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64681

Published Nov 10, 2025

In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64456

Published Nov 10, 2025

In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59458

Published Sep 17, 2025

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execu…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59457

Published Sep 17, 2025

In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59456

Published Sep 17, 2025

In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59455

Published Sep 17, 2025

In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58335

Published Aug 28, 2025

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 informatio…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58334

Published Aug 28, 2025

In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57734

Published Aug 20, 2025

In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57733

Published Aug 20, 2025

In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57732

Published Aug 20, 2025

In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 76-100 of 601 CVEsPage 4 of 25