| CVE-2026-64813 | 10 | critical | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development s | 44d ago |
| CVE-2026-64812 | 10 | critical | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | 44d ago |
| CVE-2026-62422 | 10 | critical | jetbrains / youtrack | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.1484 | 53d ago |
| CVE-2026-50242 | 10 | critical | jetbrains / hub | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 au | 78d ago |
| CVE-2026-56142 | 9.9 | critical | jetbrains / hub | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 pr | 78d ago |
| CVE-2026-63077exploited | 9.8 | critical | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent | 40d ago |
| CVE-2026-56141 | 9.8 | critical | jetbrains / hub | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 ac | 78d ago |
| CVE-2026-59792 | 9.6 | critical | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handl | 57d ago |
| CVE-2026-65906 | 8.8 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | 44d ago |
| CVE-2026-59793 | 8.8 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | 57d ago |
| CVE-2026-49368 | 8.7 | high | jetbrains / youtrack | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | 99d ago |
| CVE-2026-65908 | 8.6 | high | jetbrains / pycharm | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible | 44d ago |
| CVE-2026-64814 | 8.6 | high | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | 44d ago |
| CVE-2026-64809 | 8.4 | high | jetbrains / phpstorm | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the co | 44d ago |
| CVE-2026-64808 | 8.4 | high | jetbrains / phpstorm | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via projec | 44d ago |
| CVE-2026-64806 | 8.4 | high | jetbrains / webstorm | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the co | 44d ago |
| CVE-2026-64805 | 8.4 | high | jetbrains / webstorm | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via projec | 44d ago |
| CVE-2026-64804 | 8.4 | high | jetbrains / webstorm | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via projec | 44d ago |
| CVE-2026-44413 | 8.2 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access | 117d ago |
| CVE-2026-64815 | 8.1 | high | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | 44d ago |
| CVE-2026-59796 | 8.1 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | 57d ago |
| CVE-2026-59795 | 8.1 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | 57d ago |
| CVE-2026-49367 | 8 | high | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account | 99d ago |
| CVE-2026-64811 | 7.8 | high | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via d | 44d ago |
| CVE-2026-64807 | 7.8 | high | jetbrains / webstorm | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configurat | 44d ago |
| CVE-2026-64803 | 7.8 | high | jetbrains / goland | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the conf | 44d ago |
| CVE-2026-64802 | 7.8 | high | jetbrains / goland | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Mo | 44d ago |
| CVE-2026-49366 | 7.8 | high | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion | 99d ago |
| CVE-2026-49374 | 7.6 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | 99d ago |
| CVE-2026-49372 | 7.5 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | 99d ago |
| CVE-2026-59794 | 7.3 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | 57d ago |
| CVE-2026-53915 | 7.1 | high | jetbrains / goland | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | 78d ago |
| CVE-2026-49373 | 7.1 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | 99d ago |
| CVE-2026-49371 | 7.1 | high | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | 99d ago |
| CVE-2026-32745 | 6.3 | medium | jetbrains / datalore | In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie sett | 176d ago |