threat
engine
.sh
Back
·
··:··
Home
/
Product
/
jetbrains toolbox
Product
jetbrains toolbox
14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-43014
< 2.6
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
6.1
MEDIUM
CVE-2025-43013
< 2.6
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
6.9
MEDIUM
CVE-2025-43012
< 2.6
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
8.3
HIGH
CVE-2025-42921
< 2.6
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
4.2
MEDIUM
CVE-2024-9177
< 1.0.16
The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, themedy_social
6.4
MEDIUM
CVE-2024-24943
< 2.2
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
5.3
MEDIUM
CVE-2022-48481
< 1.28
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
5.2
MEDIUM
CVE-2020-25207
< 1.18
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
9.8
CRITICAL
CVE-2020-25013
< 1.18
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
7.5
HIGH
CVE-2020-15827
>= 1.17 and < 1.17.6856
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
7.5
HIGH
CVE-2019-18368
< 1.15.5666
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
7.3
HIGH
CVE-2019-14959
< 1.15.5605
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
5.9
MEDIUM
CVE-2019-12280
< 7.3
PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.
7.8
HIGH
CVE-2007-6139
all versions
PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP co
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin