Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Openj9 CRITICAL 9.6
CVE-2026-16441

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, exec…

No fix yet
Fix from $2,300 2026-07-21
Kura HIGH 8.2
CVE-2026-9561

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in au…

Mitigation only
Fix from $1,950 2026-07-14
Kuksa MEDIUM 6.5
CVE-2026-13699

In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point …

No fix yet
Fix from $1,600 2026-07-14
Openmq CRITICAL 9.8
CVE-2026-22886

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default adminis…

Mitigation only
Fix from $2,300 2026-03-03
Jersey HIGH 7.4
CVE-2025-12383

In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, cu…

Mitigation only
Fix from $1,950 2025-11-18
Glassfish CRITICAL 9.8
CVE-2024-9408

In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.

Mitigation only
Fix from $2,300 2025-07-16
Glassfish CRITICAL 9.8
CVE-2024-9342

In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed logi…

Mitigation only
Fix from $2,300 2025-07-16
Glassfish MEDIUM 6.1
CVE-2024-9343

In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

Mitigation only
Fix from $1,600 2025-07-16
Glassfish MEDIUM 5.4
CVE-2024-10031

In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying …

Mitigation only
Fix from $1,600 2025-07-16
Glassfish MEDIUM 5.4
CVE-2024-10032

In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

Mitigation only
Fix from $1,600 2025-07-16
Glassfish MEDIUM 6.1
CVE-2024-10029

In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.

Mitigation only
Fix from $1,600 2025-07-16
Equinox P2 HIGH 8.0
CVE-2021-41037

In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those…

Mitigation only
Fix from $1,950 2022-07-08
Keti CRITICAL 9.9
CVE-2021-32835

Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerabili…

No fix yet
Fix from $2,300 2021-09-09
Keti CRITICAL 9.9
CVE-2021-32834

Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy…

No fix yet
Fix from $2,300 2021-09-09
Cyclone Data Distribution Service HIGH 7.5
CVE-2020-18734

A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

No fix yet
Fix from $1,950 2021-08-23
Cyclone Data Distribution Service HIGH 7.5
CVE-2020-18735

A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

No fix yet
Fix from $1,950 2021-08-23
Hono HIGH 7.5
CVE-2020-27217

In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a d…

Mitigation only
Fix from $1,950 2020-11-13
Jetty CRITICAL 9.4
CVE-2019-17638EPSS 11%

In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP …

Mitigation only
Fix from $2,300 2020-07-09
Jetty MEDIUM 6.1
CVE-2019-17632

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in te…

Mitigation only
Fix from $1,600 2019-11-25
Paho Java Client HIGH 7.5
CVE-2019-11777

In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of th…

Mitigation only
Fix from $1,950 2019-09-11
Openj9 CRITICAL 9.8
CVE-2018-12548

In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept p…

Mitigation only
Fix from $2,300 2019-01-31
Ide HIGH 7.5
CVE-2017-8315

Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit t…

No fix yet
Fix from $1,950 2018-04-20
Tinydtls HIGH 7.5
CVE-2017-7243

Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packe…

Mitigation only
Fix from $1,950 2017-03-24