Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 456 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-43014 1 Jetbrains 1 Toolbox 2025-04-23 N/A 6.1 MEDIUM
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
CVE-2025-43013 1 Jetbrains 1 Toolbox 2025-04-23 N/A 6.9 MEDIUM
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
CVE-2025-42921 1 Jetbrains 1 Toolbox 2025-04-23 N/A 4.2 MEDIUM
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
CVE-2014-10002 1 Jetbrains 1 Teamcity 2025-04-12 5.0 MEDIUM N/A
Unspecified vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to obtain sensitive information via unknown vectors.
CVE-2014-10036 1 Jetbrains 1 Teamcity 2025-04-12 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.
CVE-2024-36371 1 Jetbrains 1 Teamcity 2025-02-07 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
CVE-2024-36470 1 Jetbrains 1 Teamcity 2025-02-07 N/A 8.1 HIGH
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
CVE-2024-54155 1 Jetbrains 1 Youtrack 2025-01-31 N/A 3.7 LOW
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
CVE-2024-54154 1 Jetbrains 1 Youtrack 2025-01-31 N/A 8.0 HIGH
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
CVE-2024-54153 1 Jetbrains 1 Youtrack 2025-01-31 N/A 3.1 LOW
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
CVE-2024-52555 1 Jetbrains 1 Webstorm 2025-01-31 N/A 6.3 MEDIUM
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script
CVE-2024-54158 1 Jetbrains 1 Youtrack 2025-01-30 N/A 3.5 LOW
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
CVE-2024-54157 1 Jetbrains 1 Youtrack 2025-01-30 N/A 4.3 MEDIUM
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
CVE-2024-54156 1 Jetbrains 1 Youtrack 2025-01-30 N/A 4.2 MEDIUM
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
CVE-2025-24458 1 Jetbrains 1 Youtrack 2025-01-30 N/A 7.1 HIGH
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
CVE-2025-24457 1 Jetbrains 1 Youtrack 2025-01-30 N/A 5.5 MEDIUM
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
CVE-2025-24456 1 Jetbrains 1 Hub 2025-01-30 N/A 6.7 MEDIUM
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
CVE-2025-24461 1 Jetbrains 1 Teamcity 2025-01-30 N/A 6.5 MEDIUM
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
CVE-2025-24460 1 Jetbrains 1 Teamcity 2025-01-30 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
CVE-2025-24459 1 Jetbrains 1 Teamcity 2025-01-30 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page