CVE Tools

Rider

10 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Rider, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Rider CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Rider CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-011
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-112
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical110%
  • High440%
  • Medium440%
  • Low110%

Latest CVEs

The 10 most recently published vulnerabilities affecting Rider.

  1. CVE-2025-64457In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition4.2
  2. CVE-2025-64456In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation8.4
  3. CVE-2025-43016In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session5.4
  4. CVE-2025-23385In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local...7.8
  5. CVE-2024-37051GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLi...9.3
  6. CVE-2024-24939In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible3.3
  7. CVE-2022-37396In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution4.1
  8. CVE-2022-29821In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible6.9
  9. CVE-2020-7906In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.7.5
  10. CVE-2019-14960JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store