jetbrains
57 known vulnerabilities affecting jetbrains products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-63077 | Act now | 86.5% | 9.8 | ● | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe… |
| CVE-2026-49373 | Medium | 27.1% | 7.1 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perfo… | |
| CVE-2026-75050 | Medium | 0.8% | 7.1 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible… | |
| CVE-2026-65906 | Medium | 0.5% | 8.8 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s… | |
| CVE-2026-64813 | Medium | 0.5% | 10.0 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was … | |
| CVE-2026-64812 | Medium | 0.5% | 10.0 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possib… | |
| CVE-2026-49366 | Medium | 0.5% | 7.8 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via fi… | |
| CVE-2026-49367 | Medium | 0.3% | 8.0 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via th… | |
| CVE-2026-64815 | Medium | 0.3% | 8.1 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible v… | |
| CVE-2026-62422 | Medium | 0.3% | 10.0 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.… | |
| CVE-2026-64814 | Medium | 0.3% | 8.6 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible i… | |
| CVE-2026-75045 | Medium | 0.3% | 9.1 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unau… | |
| CVE-2026-49372 | Medium | 0.3% | 7.5 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build st… | |
| CVE-2026-49371 | Medium | 0.3% | 7.1 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was po… | |
| CVE-2026-49374 | Medium | 0.2% | 7.6 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build con… | |
| CVE-2026-75044 | Medium | 0.2% | 8.1 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing… | |
| CVE-2026-75051 | Medium | 0.2% | 8.1 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between … | |
| CVE-2026-64802 | Medium | 0.2% | 7.8 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before g… | |
| CVE-2026-64803 | Medium | 0.2% | 7.8 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before g… | |
| CVE-2026-49368 | Medium | 0.2% | 8.7 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification tem… | |
| CVE-2026-75048 | Medium | 0.2% | 8.2 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block l… | |
| CVE-2026-64804 | Medium | 0.2% | 8.4 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before… | |
| CVE-2026-64805 | Medium | 0.2% | 8.4 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before… | |
| CVE-2026-64806 | Medium | 0.2% | 8.4 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before… | |
| CVE-2026-64808 | Medium | 0.2% | 8.4 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before… | |
| CVE-2026-64809 | Medium | 0.2% | 8.4 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before… | |
| CVE-2026-64807 | Medium | 0.2% | 7.8 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a … | |
| CVE-2026-65908 | Medium | 0.2% | 8.6 | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malici… | |
| CVE-2026-75056 | Medium | 0.2% | 7.8 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was poss… | |
| CVE-2026-75060 | Medium | 0.1% | 8.4 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthentic… | |
| CVE-2026-64811 | Medium | 0.1% | 7.8 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible b… | |
| CVE-2026-75047 | Low | 0.9% | 6.5 | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompre… | |
| CVE-2026-49377 | Low | 0.7% | 4.3 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default ag… | |
| CVE-2026-64800 | Low | 0.5% | 3.5 | In JetBrains GoLand before 2026.2 sensitive configuration values written to log … | |
| CVE-2026-75049 | Low | 0.3% | 6.5 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user c… | |
| CVE-2026-49386 | Low | 0.3% | 6.5 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumer… | |
| CVE-2026-49379 | Low | 0.3% | 6.5 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | |
| CVE-2026-49370 | Low | 0.2% | 3.4 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on… | |
| CVE-2026-49375 | Low | 0.2% | 6.1 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on th… | |
| CVE-2026-49385 | Low | 0.2% | 6.5 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-pr… | |
| CVE-2026-49378 | Low | 0.2% | 4.3 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via para… | |
| CVE-2026-49376 | Low | 0.2% | 6.5 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML… | |
| CVE-2026-49381 | Low | 0.2% | 3.4 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possib… | |
| CVE-2026-75046 | Low | 0.2% | 4.3 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate … | |
| CVE-2026-49369 | Low | 0.2% | 4.3 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on… | |
| CVE-2026-75053 | Low | 0.2% | 5.4 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debu… | |
| CVE-2026-49384 | Low | 0.2% | 6.1 | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cel… | |
| CVE-2026-49380 | Low | 0.2% | 3.1 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possibl… | |
| CVE-2026-64810 | Low | 0.1% | 4.3 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE n… | |
| CVE-2026-75059 | Low | 0.1% | 4.4 | In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was … |
Page 1 of 2
Next →