Vulnerabilities
Vulnerable Software
Jetbrains:  Security Vulnerabilities
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
CVSS Score
5.5
EPSS Score
0.001
Published
2026-08-17
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
CVSS Score
8.1
EPSS Score
0.002
Published
2026-08-17
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVSS Score
9.1
EPSS Score
0.003
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
CVSS Score
6.5
EPSS Score
0.009
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
CVSS Score
8.2
EPSS Score
0.002
Published
2026-08-17
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
CVSS Score
6.5
EPSS Score
0.003
Published
2026-08-17
CVE-2026-63077
Known exploited
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVSS Score
9.8
EPSS Score
0.865
Published
2026-07-27
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
CVSS Score
8.8
EPSS Score
0.005
Published
2026-07-23
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
CVSS Score
8.6
EPSS Score
0.002
Published
2026-07-23


Contact Us

Shodan ® - All rights reserved