Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jetbrains intellij idea vulnerabilities and exploits
(subscribe to this query)
7.4
CVSSv3
CVE-2020-7904
In JetBrains IntelliJ IDEA prior to 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
Jetbrains Intellij Idea
7.5
CVSSv3
CVE-2020-7914
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.
Jetbrains Intellij Idea
9.8
CVSSv3
CVE-2019-9186
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote malicious users to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost inter...
Jetbrains Intellij Idea
7.8
CVSSv3
CVE-2022-40978
The installer of JetBrains IntelliJ IDEA prior to 2022.2.2 was vulnerable to EXE search order hijacking
Jetbrains Intellij Idea
9.8
CVSSv3
CVE-2023-51655
In JetBrains IntelliJ IDEA prior to 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
Jetbrains Intellij Idea
8.1
CVSSv3
CVE-2019-9872
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configur...
Jetbrains Intellij Idea
9.8
CVSSv3
CVE-2019-9873
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, a...
Jetbrains Intellij Idea
7.5
CVSSv3
CVE-2017-8316
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
Jetbrains Intellij Idea
7.8
CVSSv3
CVE-2022-24346
In JetBrains IntelliJ IDEA prior to 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.
Jetbrains Intellij Idea
7.8
CVSSv3
CVE-2022-37009
In JetBrains IntelliJ IDEA prior to 2022.2 local code execution via a Vagrant executable was possible
Jetbrains Intellij Idea
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-40673
CVE-2024-36674
CVE-2024-27348
unspecified
CVE-2024-24919
CVE-2024-4870
malicious code
CVE-2024-2019
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »