Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
intellij idea vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2024-24940
In JetBrains IntelliJ IDEA prior to 2023.3.3 path traversal was possible when unpacking archives
Jetbrains Intellij Idea
5.3
CVSSv3
CVE-2024-24941
In JetBrains IntelliJ IDEA prior to 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
Jetbrains Intellij Idea
9.8
CVSSv3
CVE-2023-51655
In JetBrains IntelliJ IDEA prior to 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
Jetbrains Intellij Idea
7.8
CVSSv3
CVE-2023-39261
In JetBrains IntelliJ IDEA prior to 2023.2 plugin for Space was requesting excessive permissions
Jetbrains Intellij Idea
3.3
CVSSv3
CVE-2023-38069
In JetBrains IntelliJ IDEA prior to 2023.1.4 license dialog could be suppressed in certain cases
Jetbrains Intellij Idea
7.5
CVSSv3
CVE-2022-48430
In JetBrains IntelliJ IDEA prior to 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
Jetbrains Intellij Idea
7.8
CVSSv3
CVE-2022-48431
In JetBrains IntelliJ IDEA prior to 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
Jetbrains Intellij Idea
8.8
CVSSv3
CVE-2022-48432
In JetBrains IntelliJ IDEA prior to 2023.1 the bundled version of Chromium wasn't sandboxed.
Jetbrains Intellij Idea
7.5
CVSSv3
CVE-2022-48433
In JetBrains IntelliJ IDEA prior to 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
Jetbrains Intellij Idea
7.5
CVSSv3
CVE-2022-47895
In JetBrains IntelliJ IDEA prior to 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
Jetbrains Intellij Idea
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
XXE
CVE-2024-34490
SQL injection
CVE-2024-34488
CVE-2024-4507
CVE-2023-7028
CVE-2024-23187
TCP
CVE-2024-4439
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »