Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
intellij idea vulnerabilities and exploits
(subscribe to this query)
5.9
CVSSv3
CVE-2019-14954
JetBrains IntelliJ IDEA prior to 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
Jetbrains Intellij Idea
9.8
CVSSv3
CVE-2019-9873
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, a...
Jetbrains Intellij Idea
7.5
CVSSv3
CVE-2022-48430
In JetBrains IntelliJ IDEA prior to 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
Jetbrains Intellij Idea
7.8
CVSSv3
CVE-2022-48431
In JetBrains IntelliJ IDEA prior to 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
Jetbrains Intellij Idea
8.8
CVSSv3
CVE-2022-48432
In JetBrains IntelliJ IDEA prior to 2023.1 the bundled version of Chromium wasn't sandboxed.
Jetbrains Intellij Idea
7.5
CVSSv3
CVE-2022-48433
In JetBrains IntelliJ IDEA prior to 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
Jetbrains Intellij Idea
8.1
CVSSv3
CVE-2019-9872
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configur...
Jetbrains Intellij Idea
5.5
CVSSv3
CVE-2022-28651
In JetBrains IntelliJ IDEA prior to 2021.3.3 it was possible to get passwords from protected fields
Jetbrains Intellij Idea
7.8
CVSSv3
CVE-2021-25758
In JetBrains IntelliJ IDEA prior to 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
Jetbrains Intellij Idea
9.8
CVSSv3
CVE-2019-10104
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote malicious user to execute code when the configuration is running, because a JMX server listened on all ...
Jetbrains Intellij Idea
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »