Vulnerabilities
Vulnerable Software
Security Vulnerabilities
In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
CVSS Score
6.5
EPSS Score
0.008
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
CVSS Score
7.6
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
CVSS Score
4.7
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
CVSS Score
2.7
EPSS Score
0.002
Published
2026-09-30
In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
CVSS Score
4.8
EPSS Score
0.001
Published
2026-09-30
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
CVSS Score
7.7
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVSS Score
5.9
EPSS Score
0.003
Published
2026-09-30
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
CVSS Score
8.1
EPSS Score
0.004
Published
2026-09-30
In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVSS Score
4.3
EPSS Score
0.002
Published
2026-09-30


Contact Us

Shodan ® - All rights reserved