jetbrains

543 tracked vulnerabilities.

CVE-2025-43015 HIGH
JetBrains RubyMine < 2025.1 - Insecure Default Port Binding in Remote Interpreter
Apr 17, 2025
CVSS 8.3
EPSS 0.00
CVE-2025-43014 MEDIUM
JetBrains Toolbox < 2.6 - Missing Critical Step in SSH Authentication
Apr 17, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-43013 MEDIUM
JetBrains Toolbox App <2.6 - Info Disclosure
Apr 17, 2025
CVSS 6.9
EPSS 0.00
CVE-2025-43012 HIGH
JetBrains Toolbox App <2.6 - Command Injection
Apr 17, 2025
CVSS 8.3
EPSS 0.00
CVE-2025-42921 MEDIUM
JetBrains Toolbox App <2.6 - Privilege Escalation
Apr 17, 2025
CVSS 4.2
EPSS 0.00
CVE-2025-32054 LOW
JetBrains IntelliJ IDEA 2024.2.4-2024.3.0 - Sensitive Information Exposure in Log File
Apr 03, 2025
CVSS 3.3
EPSS 0.00
CVE-2025-31141 LOW
JetBrains TeamCity < 2025.03 - Credential Leakage via Cloud Profiles Page Exception
Mar 27, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-31140 MEDIUM
JetBrains TeamCity < 2025.03 - Stored Cross-Site Scripting on Cloud Profiles Page
Mar 27, 2025
CVSS 4.6
EPSS 0.33
CVE-2025-31139 MEDIUM
JetBrains TeamCity < 2025.03 - Sensitive Information Exposure in Build Log
Mar 27, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-29932 MEDIUM
JetBrains GoLand < 2025.1 - XML External Entity Injection during Debugging
Mar 25, 2025
CVSS 4.1
EPSS 0.00
CVE-2025-29904 MEDIUM
JetBrains Ktor < 3.1.1 - HTTP Request Smuggling
Mar 12, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-29903 MEDIUM
JetBrains Runtime <21.0.6b872.80 - Code Injection
Mar 12, 2025
CVSS 5.2
EPSS 0.00
CVE-2025-26493 MEDIUM
JetBrains TeamCity < 2024.12.2 - DOM-based Cross-Site Scripting on Code Inspection Report Tab
Feb 11, 2025
CVSS 4.6
EPSS 0.16
CVE-2025-26492 HIGH
JetBrains TeamCity < 2024.12.2 - Insufficiently Protected Kubernetes Credentials
Feb 11, 2025
CVSS 7.7
EPSS 0.00
CVE-2025-23385 HIGH
JetBrains dotTrace, ReSharper, Rider < 2024.1.7 & ETW Host Service < 16.43 - Local Privilege Escalation
Jan 28, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-24461 MEDIUM
JetBrains TeamCity < 2024.12.1 - Unauthenticated Decryption of Connection Secrets via Test Connection Endpoint
Jan 21, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-24460 MEDIUM
JetBrains TeamCity < 2024.12.1 - Unauthenticated Project Name Disclosure via Agent Pool
Jan 21, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-24459 MEDIUM
JetBrains TeamCity < 2024.12.1 - Reflected Cross-Site Scripting on Vault Connection Page
Jan 21, 2025
CVSS 4.6
EPSS 0.22
CVE-2025-24458 HIGH
JetBrains YouTrack < 2024.3.55417 - Account Takeover via Spoofed Email and Helpdesk Integration
Jan 21, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-24457 MEDIUM
JetBrains YouTrack < 2024.3.55417 - Sensitive Information Exposure via Log File Insertion
Jan 21, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-24456 MEDIUM
JetBrains Hub < 2024.3.55417 - Privilege Escalation via LDAP Authentication Mapping
Jan 21, 2025
CVSS 6.7
EPSS 0.00
CVE-2024-56356 MEDIUM
JetBrains TeamCity < 2024.12 - XML External Entity Injection via Insecure XML Parser Configuration
Dec 20, 2024
CVSS 5.9
EPSS 0.00
CVE-2024-56355 MEDIUM
JetBrains TeamCity < 2024.12 - Cross-Site Scripting via RemoteBuildLogController Response
Dec 20, 2024
CVSS 4.6
EPSS 0.34
CVE-2024-56354 MEDIUM
JetBrains TeamCity < 2024.12 - Insufficiently Protected Credentials
Dec 20, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-56353 MEDIUM
JetBrains TeamCity <2024.12 - Info Disclosure
Dec 20, 2024
CVSS 5.5
EPSS 0.00