threat
engine
.sh
Back
·
··:··
Home
/
Product
/
jetbrains pycharm
Product
jetbrains pycharm
8 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-25847
< 2025.3.2
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
8.2
HIGH
CVE-2024-37051
< 2023.1.6
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023
9.3
CRITICAL
CVE-2022-29821
< 2022.1
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
6.9
MEDIUM
CVE-2022-29820
< 2022.1
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
3.0
LOW
CVE-2021-45977
all versions
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2
9.8
CRITICAL
CVE-2021-30005
< 2020.3.4
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project fr
7.8
HIGH
CVE-2020-11694
all versions
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2
7.5
HIGH
CVE-2019-14958
< 2019.2
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific si
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin