Filtered by vendor Jetbrains
Subscriptions
Filtered by product Intellij Idea
Subscriptions
Total
81 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86505 | 1 Jetbrains | 1 Intellij Idea | 2026-09-08 | 3.3 Low |
| In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace | ||||
| CVE-2026-86504 | 1 Jetbrains | 1 Intellij Idea | 2026-09-08 | 7.8 High |
| In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution | ||||
| CVE-2026-86503 | 1 Jetbrains | 1 Intellij Idea | 2026-09-08 | 3.3 Low |
| In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching | ||||
| CVE-2026-86502 | 1 Jetbrains | 1 Intellij Idea | 2026-09-08 | 8.4 High |
| In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts | ||||
| CVE-2026-86501 | 1 Jetbrains | 1 Intellij Idea | 2026-09-08 | 2.8 Low |
| In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log | ||||
| CVE-2026-75052 | 1 Jetbrains | 1 Intellij Idea | 2026-09-01 | 3.6 Low |
| In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects | ||||
| CVE-2026-75058 | 1 Jetbrains | 1 Intellij Idea | 2026-08-17 | 5.5 Medium |
| In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | ||||
| CVE-2026-75054 | 1 Jetbrains | 1 Intellij Idea | 2026-08-17 | 6.3 Medium |
| In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | ||||
| CVE-2026-75053 | 1 Jetbrains | 1 Intellij Idea | 2026-08-17 | 5.4 Medium |
| In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | ||||
| CVE-2026-75057 | 1 Jetbrains | 1 Intellij Idea | 2026-08-17 | 6.2 Medium |
| In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | ||||
| CVE-2026-75055 | 1 Jetbrains | 1 Intellij Idea | 2026-08-17 | 5.5 Medium |
| In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | ||||
| CVE-2026-75056 | 1 Jetbrains | 1 Intellij Idea | 2026-08-17 | 7.8 High |
| In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | ||||
| CVE-2026-64810 | 1 Jetbrains | 1 Intellij Idea | 2026-08-04 | 4.3 Medium |
| In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | ||||
| CVE-2026-64811 | 1 Jetbrains | 1 Intellij Idea | 2026-08-04 | 7.8 High |
| In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | ||||
| CVE-2026-64815 | 1 Jetbrains | 1 Intellij Idea | 2026-08-04 | 8.1 High |
| In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | ||||
| CVE-2026-64812 | 1 Jetbrains | 1 Intellij Idea | 2026-08-03 | 10 Critical |
| In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | ||||
| CVE-2026-64813 | 1 Jetbrains | 1 Intellij Idea | 2026-08-03 | 10 Critical |
| In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | ||||
| CVE-2026-64814 | 1 Jetbrains | 1 Intellij Idea | 2026-08-03 | 8.6 High |
| In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | ||||
| CVE-2026-59792 | 1 Jetbrains | 1 Intellij Idea | 2026-08-01 | 9.6 Critical |
| In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible | ||||
| CVE-2026-49382 | 1 Jetbrains | 1 Intellij Idea | 2026-06-01 | 4.5 Medium |
| In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin | ||||