Search Results (580 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-49372 1 Jetbrains 1 Teamcity 2026-06-02 7.5 High
In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49371 1 Jetbrains 1 Teamcity 2026-06-02 7.1 High
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-49382 1 Jetbrains 1 Intellij Idea 2026-06-01 4.5 Medium
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
CVE-2026-49366 1 Jetbrains 1 Intellij Idea 2026-06-01 7.8 High
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-49383 1 Jetbrains 1 Intellij Idea 2026-06-01 3.3 Low
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
CVE-2026-49367 1 Jetbrains 1 Intellij Idea 2026-06-01 8 High
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-49368 1 Jetbrains 1 Youtrack 2026-06-01 8.7 High
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
CVE-2026-49369 1 Jetbrains 1 Youtrack 2026-06-01 4.3 Medium
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
CVE-2026-49370 1 Jetbrains 1 Youtrack 2026-06-01 3.4 Low
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
CVE-2026-49384 1 Jetbrains 1 Pycharm 2026-06-01 6.1 Medium
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
CVE-2026-49385 1 Jetbrains 1 Youtrack 2026-06-01 6.5 Medium
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
CVE-2026-49386 1 Jetbrains 1 Youtrack 2026-06-01 6.5 Medium
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
CVE-2026-44413 1 Jetbrains 1 Teamcity 2026-05-12 8.2 High
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-41882 1 Jetbrains 1 Intellij Idea 2026-05-05 7.4 High
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
CVE-2026-41153 1 Jetbrains 1 Junie 2026-04-27 5.8 Medium
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
CVE-2024-27199 1 Jetbrains 1 Teamcity 2026-04-21 7.3 High
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
CVE-2026-33392 1 Jetbrains 1 Youtrack 2026-04-20 7.2 High
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
CVE-2026-25848 1 Jetbrains 1 Hub 2026-04-18 9.1 Critical
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
CVE-2026-28196 1 Jetbrains 1 Teamcity 2026-04-18 2.3 Low
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
CVE-2026-25846 1 Jetbrains 1 Youtrack 2026-04-17 6.5 Medium
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs