Products

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
JetBrains vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CWE-502Jul 27, 20261 related artifact
CVSS9.8v3.1EPSS10.7%PoCs4SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Generated title:JetBrains TeamCity Git VCS Root Code Execution

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

CWE-94Jul 23, 2026
CVSS9.1v3.1EPSS0.421%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains PyCharm Arbitrary Code Execution via Malicious Python Executable on Untrusted Project Open

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

CWE-829Jul 23, 2026
CVSS8.6v3.1EPSS0.126%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains TeamCity Kotlin DSL Sandbox Escape Code Execution

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

CWE-94Jul 23, 2026
CVSS8.8v3.1EPSS0.417%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains IntelliJ IDEA UI Designer Form File Code Injection

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

CWE-94Jul 23, 2026
CVSS8.1v3.1EPSS0.33%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains IntelliJ IDEA Remote Development Unauthorized File Access

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

CWE-862Jul 23, 2026
CVSS8.6v3.1EPSS0.315%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains IntelliJ IDEA Remote Development Session Unauthorized Settings Modification

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

CWE-602Jul 23, 2026
CVSS10.0v3.1EPSS0.393%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains IntelliJ IDEA Remote Development Session Unauthorized Input Injection

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

CWE-306Jul 23, 2026
CVSS10.0v3.1EPSS0.363%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains IntelliJ IDEA Development Container Configuration Arbitrary Code Execution

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

CWE-829Jul 23, 2026
CVSS7.8v3.1EPSS0.126%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains IntelliJ IDEA HTML Injection in IDE Notification

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

CWE-79Jul 23, 2026
CVSS4.3v3.1EPSS0.149%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains PhpStorm Arbitrary Code Execution via Configured Interpreter Before Project Trust

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

CWE-829Jul 23, 2026
CVSS8.4v3.1EPSS0.14%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains PhpStorm Arbitrary Code Execution via Project Tooling Before Project Trust

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

CWE-829Jul 23, 2026
CVSS8.4v3.1EPSS0.14%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains WebStorm Arbitrary Code Execution via Project-Supplied Linter Configuration

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

CWE-829Jul 23, 2026
CVSS7.8v3.1EPSS0.126%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains WebStorm Arbitrary Code Execution via Untrusted Node.js Interpreter

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

CWE-829Jul 23, 2026
CVSS8.4v3.1EPSS0.14%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains WebStorm Arbitrary Code Execution via Untrusted Project-Local Package Manager Tooling

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

CWE-829Jul 23, 2026
CVSS8.4v3.1EPSS0.14%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains WebStorm Arbitrary Code Execution via Project-Local Linter Tooling

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

CWE-829Jul 23, 2026
CVSS8.4v3.1EPSS0.14%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains GoLand Code Injection via Configured Go SDK

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

CWE-94Jul 23, 2026
CVSS7.8v3.1EPSS0.143%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains GoLand Go Modules Integration Code Injection

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

CWE-94Jul 23, 2026
CVSS7.8v3.1EPSS0.143%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains GoLand Sensitive Configuration Information Disclosure in Log Files

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

CWE-532Jul 23, 2026
CVSS3.5v3.1EPSS0.491%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Authentication Bypass via Direct Database Access

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

CWE-306Jul 14, 2026
CVSS10.0v3.1EPSS0.329%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains YouTrack Stored Cross-Site Scripting via Article Titles in Digest Emails

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

CWE-79Jul 10, 2026
CVSS3.5v3.1EPSS0.391%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains TeamCity Missing Authorization on Pipeline Modification

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

CWE-862Jul 10, 2026
CVSS8.1v3.1EPSS0.273%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains TeamCity Stored Cross-Site Scripting via Unauthenticated Agent Registration

In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible

CWE-79Jul 10, 2026
CVSS8.1v3.1EPSS0.264%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains TeamCity Cloud Profile Page Stored Cross-Site Scripting

In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data

CWE-79Jul 10, 2026
CVSS7.3v3.1EPSS0.208%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains TeamCity Perforce VCS Integration Arbitrary File Access

In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration

CWE-73Jul 10, 2026
CVSS8.8v3.1EPSS0.377%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX