Hub

Vendor:

First CVE: Jul 3, 2019 · Active for 7 years

36
Total CVEs
More Total CVEs than 97% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hub over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2019
7 years ago
Most Recent CVE
Jun 19, 2026
39 days ago

CVE Severity & Scoring

Hub36 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network36 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (91.7%)
High3 (8.3%)
Unknown0 (0.0%)
User Interaction
None29 (80.6%)
Unknown0 (0.0%)
Required7 (19.4%)
Privileges Required
Low8 (22.2%)
High2 (5.6%)
None26 (72.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administ
Jun 19, 20269.839NONO
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
Jun 19, 20269.838NONO
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts
Jun 19, 20268.835NONO
In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible
Feb 9, 20269.832NONO
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
Nov 9, 20219.831NONO
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
Apr 24, 20239.829NONO
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
Feb 25, 20229.129NONO
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
Aug 6, 20219.829NONO
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
Nov 18, 20227.525NONO
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
Nov 10, 20257.524NONO

Exploit Exposure

Signals from CVEs in this product scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (36 CVEs).

Media Mentions

Signals from CVEs in this product scope (36 CVEs).

Top CNAs Publishing CVEs For Hub

Top CWEs

Versions

No cataloged versions.