58 Total CVEs
58 AI Analyzed
2 CISA KEV
13 Critical

Profile

3.4% ended up actively exploited 2 of 58 added to CISA KEV
22% rated critical (CVSS 9.0+) 13 critical, 45 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

50 CVEs in the last 12 months

Products

  • YouTrack17
  • TeamCity12
  • IntelliJ IDEA10
  • Hub4
  • WebStorm4
  • PyCharm3
  • PhpStorm2
  • GoLand2

11 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-58 of 58 CVEs
CVE-2026-86504
Analyzed
7.8
JetBrains IntelliJ IDEA

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

2026-09-08
Full analysis →
CVE-2026-86502
Analyzed
8.4
JetBrains IntelliJ IDEA

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development...

2026-09-08
Full analysis →
CVE-2026-86498
Analyzed
7.7
JetBrains YouTrack

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permi...

2026-09-08
Full analysis →
CVE-2026-86494
Analyzed
7.7
JetBrains YouTrack

In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

2026-09-08
Full analysis →
CVE-2026-86492
Analyzed
8.5
JetBrains YouTrack

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

2026-09-08
Full analysis →
CVE-2026-86482
Analyzed
8.8
JetBrains YouTrack

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

2026-09-08
Full analysis →
CVE-2026-86480
Analyzed
9.8
JetBrains Hub

JetBrains Hub contains a flaw allowing unauthenticated attackers to register a trusted service, resulting in the acquisition of superuser privileges.

2026-09-08
Full analysis →
CVE-2026-86479
Analyzed
8
JetBrains YouTrack

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDO...

2026-09-08
Full analysis →
CVE-2026-86478
Analyzed
9.8
JetBrains YouTrack

An improper authentication vulnerability in the JetBrains YouTrack Helpdesk feature allows unauthenticated attackers to perform account takeovers by s...

2026-09-08
Full analysis →
CVE-2026-75045
Analyzed
9.1
JetBrains YouTrack

JetBrains YouTrack is vulnerable to unauthorized database backup downloads by unauthenticated attackers due to an issue with shared draft signatures.

2026-08-18
Full analysis →
CVE-2026-64813
Analyzed
10
JetBrains IntelliJ IDEA

JetBrains IntelliJ IDEA is vulnerable to unauthorized settings modification during Remote Development sessions, enabling unauthenticated attackers to...

2026-07-24
Full analysis →
CVE-2026-64812
Analyzed
10
JetBrains IntelliJ IDEA

JetBrains IntelliJ IDEA is susceptible to unauthorized input injection during Remote Development sessions, allowing unauthenticated remote attackers t...

2026-07-24
Full analysis →
CVE-2026-63077
KEV Analyzed
9.8
JetBrains TeamCity

An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.

2026-07-28
Full analysis →
CVE-2026-62422
Analyzed
10
JetBrains YouTrack

JetBrains YouTrack is affected by an authentication bypass vulnerability allowing unauthenticated attackers to gain administrative access via direct d...

2026-07-15
Full analysis →
CVE-2026-59792
Analyzed
9.6
JetBrains IntelliJ IDEA

JetBrains IntelliJ IDEA is vulnerable to remote code execution due to path traversal in project workspace ID handling.

2026-07-11
Full analysis →
CVE-2026-56142
Analyzed
9.9
JetBrains Hub

JetBrains Hub is susceptible to privilege escalation by allowing the attachment of unauthorized authentication details to user accounts.

2026-06-20
Full analysis →
CVE-2026-50242
Analyzed
10
JetBrains Hub

JetBrains Hub contains an authentication bypass vulnerability via direct database access that allows unauthorized administrative control.

2026-06-20
Full analysis →
CVE-2026-25848
Analyzed
9.1
JetBrains Hub

JetBrains Hub versions prior to 2025.3.119807 contain an authentication bypass vulnerability that allows unauthenticated attackers to perform administ...

2026-02-10
Full analysis →
CVE-2025-64689
Analyzed
9.6
JetBrains

In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token

2025-11-11
Full analysis →
CVE-2024-27199
KEV Analyzed
9.5
JetBrains TeamCity

JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-21
Full analysis →