JetBrains s.r.o.

First CVE: Apr 5, 2022Active for: 4 years
356
CVEs Published
More CVEs Published than 85% of tracked CNAs
71.2
Avg CVEs / Year
More Avg CVEs / Year than 88% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked CNAs
0.8%
In CISA KEV
Higher KEV Rate than 87% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by JetBrains s.r.o. as a CNA, 98.9% affect products that JetBrains s.r.o. develops as a vendor.

98.9%
Self-reported: 352Third-party: 4

Of all the CVEs published that affect products developed by JetBrains s.r.o., 59.0% are self-published by JetBrains s.r.o. as a CNA.

59.0%
41.0%
Self-published: 352Published by other CNAs: 245

Trends Over Time

The number and severity of CVEs published by JetBrains s.r.o. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2022
4 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by JetBrains s.r.o. as a CNA, regardless of affected vendor or product.

356 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
Mar 4, 20249.899YESYES
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Sep 19, 20239.899YESYES
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
Mar 4, 20247.397YESYES
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
Feb 6, 20249.872NOYES
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
Mar 28, 20245.457NONO
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
Mar 27, 20235.453NONO
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
May 31, 20235.448NONO
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
May 31, 20235.447NONO
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to adm
Jul 14, 202610.043NONO
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
Jul 10, 20269.843NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA356 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local56 (15.7%)
Network298 (83.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.6%)
Attack Complexity
Low345 (96.9%)
High11 (3.1%)
Unknown0 (0.0%)
User Interaction
None224 (62.9%)
Unknown0 (0.0%)
Required132 (37.1%)
Privileges Required
Low148 (41.6%)
High28 (7.9%)
None180 (50.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (356 CVEs).

CISA KEV
3 CVEs
0.8% of CVEs· 87th percentile
Metasploit
2 CVEs
0.6% of CVEs· 84th percentile
Nuclei
4 CVEs
1.1% of CVEs· 81st percentile
ExploitDB
2 CVEs
0.6% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by JetBrains s.r.o. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by JetBrains s.r.o. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs