Vulnerabilidades en JetBrains

406 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2026-75059MEDIUMIn JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possibleEPSS 0.1%CVE-2026-49382MEDIUMIn JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright pluginEPSS 0.1%CVE-2025-23385HIGHIn JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 202EPSS 0.1%CVE-2026-75057MEDIUMIn JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE logEPSS 0.1%CVE-2026-75052LOWIn JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projectsEPSS 0.1%CVE-2025-54529LOWIn JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integrationEPSS 0.1%CVE-2022-46825MEDIUMIn JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.EPSS 0.1%CVE-2025-57729MEDIUMIn JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server startEPSS 0.1%CVE-2026-86504HIGHIn JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code executEPSS 0.1%CVE-2026-28196LOWIn JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on diskEPSS 0.1%CVE-2026-64811HIGHIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container confiEPSS 0.1%CVE-2026-86487LOWIn JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas contentEPSS 0.1%CVE-2026-75054MEDIUMIn JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projectsEPSS 0.1%CVE-2026-75058MEDIUMIn JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importersEPSS 0.1%CVE-2026-75055MEDIUMIn JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXEEPSS 0.1%CVE-2025-57732HIGHIn JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownershipEPSS 0.1%CVE-2024-52555MEDIUMIn JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer scriptEPSS 0.1%CVE-2026-86485LOWIn JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooksEPSS 0.1%CVE-2026-49383LOWIn JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possibleEPSS 0.1%CVE-2026-86505LOWIn JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains MarketplaceEPSS 0.1%