Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 582 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-31141 1 Jetbrains 1 Teamcity 2026-06-17 N/A 2.7 LOW
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
CVE-2025-31140 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
CVE-2025-31139 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
CVE-2025-29932 1 Jetbrains 1 Goland 2026-06-17 N/A 4.1 MEDIUM
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
CVE-2025-29904 1 Jetbrains 1 Ktor 2026-06-17 N/A 5.3 MEDIUM
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
CVE-2025-29903 1 Jetbrains 1 Runtime 2026-06-17 N/A 5.2 MEDIUM
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
CVE-2025-26493 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
CVE-2025-26492 1 Jetbrains 1 Teamcity 2026-06-17 N/A 7.7 HIGH
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
CVE-2025-24461 1 Jetbrains 1 Teamcity 2026-06-17 N/A 6.5 MEDIUM
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
CVE-2025-24460 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
CVE-2025-24459 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
CVE-2025-24458 1 Jetbrains 1 Youtrack 2026-06-17 N/A 7.1 HIGH
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
CVE-2025-24457 1 Jetbrains 1 Youtrack 2026-06-17 N/A 5.5 MEDIUM
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
CVE-2025-24456 1 Jetbrains 1 Hub 2026-06-17 N/A 6.7 MEDIUM
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
CVE-2025-23385 1 Jetbrains 4 Dottrace, Etw Host Service, Resharper and 1 more 2026-06-17 N/A 7.8 HIGH
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
CVE-2024-56356 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.9 MEDIUM
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
CVE-2024-56355 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
CVE-2024-56354 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.5 MEDIUM
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
CVE-2024-56353 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.5 MEDIUM
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
CVE-2024-56352 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page