Filtered by vendor Jetbrains
Subscribe
Total
582 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-67742 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 3.8 LOW |
| In JetBrains TeamCity before 2025.11 path traversal was possible via file upload | |||||
| CVE-2025-67741 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute | |||||
| CVE-2025-67740 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 2.7 LOW |
| In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata | |||||
| CVE-2025-67739 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 3.1 LOW |
| In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure | |||||
| CVE-2025-64773 | 1 Jetbrains | 1 Youtrack | 2026-06-17 | N/A | 2.7 LOW |
| In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit | |||||
| CVE-2025-64685 | 1 Jetbrains | 1 Youtrack | 2026-06-17 | N/A | 8.1 HIGH |
| In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure | |||||
| CVE-2025-64684 | 1 Jetbrains | 1 Youtrack | 2026-06-17 | N/A | 4.3 MEDIUM |
| In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form | |||||
| CVE-2025-64683 | 1 Jetbrains | 1 Hub | 2026-06-17 | N/A | 5.3 MEDIUM |
| In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API | |||||
| CVE-2025-64682 | 1 Jetbrains | 1 Hub | 2026-06-17 | N/A | 2.7 LOW |
| In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit | |||||
| CVE-2025-64681 | 1 Jetbrains | 1 Hub | 2026-06-17 | N/A | 2.7 LOW |
| In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations | |||||
| CVE-2025-64457 | 1 Jetbrains | 3 Dottrace, Resharper, Rider | 2026-06-17 | N/A | 4.2 MEDIUM |
| In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition | |||||
| CVE-2025-64456 | 1 Jetbrains | 1 Resharper | 2026-06-17 | N/A | 8.4 HIGH |
| In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation | |||||
| CVE-2025-59458 | 1 Jetbrains | 1 Junie | 2026-06-17 | N/A | 8.3 HIGH |
| In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation | |||||
| CVE-2025-59457 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 7.7 HIGH |
| In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows | |||||
| CVE-2025-59456 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.5 MEDIUM |
| In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload | |||||
| CVE-2025-59455 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.2 MEDIUM |
| In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition | |||||
| CVE-2025-58335 | 1 Jetbrains | 1 Junie | 2026-06-17 | N/A | 5.5 MEDIUM |
| In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function | |||||
| CVE-2025-58334 | 1 Jetbrains | 1 Ide Services | 2026-06-17 | N/A | 8.1 HIGH |
| In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves | |||||
| CVE-2025-57734 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.3 MEDIUM |
| In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files | |||||
| CVE-2025-57733 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.5 MEDIUM |
| In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content | |||||
