CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “jetbrains”

535 vulnerabilities found for “jetbrains”

Page 1 of 27

CVE-2025-29932
MEDIUM4.1

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

jetbrains / goland
Network
Published Mar 25, 2025
Page 1 of 27
CVE-2024-37051
CRITICAL9.3

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

jetbrains / aqua+43
Network
Published Jun 10, 2024
CVE-2022-28651
HIGH8.4

In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields

jetbrains / intellij_idea
Local
Published Apr 5, 2022
CVE-2021-45977
CRITICAL9.8

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

jetbrains / clion+10
Network
Published Feb 25, 2022
CVE-2022-24345
HIGH7.8

In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

jetbrains / intellij_idea
Local
Published Feb 25, 2022
CVE-2022-24346
HIGH7.8

In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

jetbrains / intellij_idea
Local
Published Feb 25, 2022
CVE-2021-43192
MEDIUM5.3

In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.

jetbrains / youtrack_mobile
Network
Published Nov 9, 2021
CVE-2021-43187
MEDIUM5.3

In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.

jetbrains / youtrack_mobile
Network
Published Nov 9, 2021
CVE-2021-43191
MEDIUM5.3

JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.

jetbrains / youtrack_mobile
Network
Published Nov 9, 2021
CVE-2021-43188
HIGH7.3

In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

jetbrains / youtrack_mobile
Network
Published Nov 9, 2021
CVE-2021-43189
HIGH7.3

In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

jetbrains / youtrack_mobile
Network
Published Nov 9, 2021
CVE-2021-43190
MEDIUM5.3

In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.

jetbrains / youtrack_mobile
Network
Published Nov 9, 2021
CVE-2021-29263
HIGH7.8

In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.

jetbrains / intellij_idea
Local
Published May 11, 2021
CVE-2021-30504
HIGH7.5

In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.

jetbrains / intellij_idea
Network
Published May 11, 2021
CVE-2021-30006
HIGH7.5

In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

jetbrains / intellij_idea
Network
Published May 11, 2021
CVE-2021-25758
HIGH7.8

In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.

jetbrains / intellij_idea
Local
Published Feb 3, 2021
CVE-2021-25756
MEDIUM5.3

In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.

jetbrains / intellij_idea
Network
Published Feb 3, 2021
CVE-2020-27622
MEDIUM5.3

In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.

jetbrains / intellij_idea
Network
Published Nov 16, 2020
CVE-2020-11690
CRITICAL9.8

In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.

jetbrains / intellij_idea
Network
Published Apr 22, 2020
CVE-2020-11685
HIGH7.5

In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

jetbrains / goland
Network
Published Apr 22, 2020