Hub
Vendor:
First CVE: Jul 3, 2019 · Active for 7 years
36
Total CVEs
More Total CVEs than 97% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hub over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2019
7 years ago
Most Recent CVE
Jun 19, 2026
39 days ago
CVE Severity & Scoring
Hub36 CVEs
44%
28%
22%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network36 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (91.7%)
High3 (8.3%)
Unknown0 (0.0%)
User Interaction
None29 (80.6%)
Unknown0 (0.0%)
Required7 (19.4%)
Privileges Required
Low8 (22.2%)
High2 (5.6%)
None26 (72.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50242CRITICAL In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administ | Jun 19, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-56141CRITICAL In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 account takeover via predictable restore codes was possible | Jun 19, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-56142HIGH In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 privilege escalation by attaching authentication details to accounts | Jun 19, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-25848CRITICAL In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible | Feb 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2021-43183CRITICAL In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. | Nov 9, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-48477CRITICAL In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
| Apr 24, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-25260CRITICAL JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF). | Feb 25, 2022 | 9.1 | 29 | NO | NO |
CVE-2021-36209CRITICAL In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset. | Aug 6, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-45471HIGH In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address | Nov 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-64683HIGH In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API | Nov 10, 2025 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (36 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (36 CVEs).
Media Mentions
Signals from CVEs in this product scope (36 CVEs).
Top CNAs Publishing CVEs For Hub
Top CWEs
Versions
No cataloged versions.