Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-46580 In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could ov… Theia 1.71.0+ Fix from $1,9502026-06-18 HIGH 8.8 CVE-2026-44688 In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without disti… Theia 1.71.0+ Fix from $1,9502026-06-18 MEDIUM 6.5 CVE-2026-22551 In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external… Theia 1.71.0+ Fix from $1,6002026-06-18 CRITICAL 9.8 CVE-2026-9158 In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling poin… 4diac Forte after 3.1.0 Fix from $2,3002026-06-18 CRITICAL 9.6 CVE-2026-2587 A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget hand… Glassfish 8.0.2+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-2586 An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can … Glassfish 8.0.2+ Fix from $2,3002026-05-19 MEDIUM 5.3 CVE-2026-6860 A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if… Vert.x after 5.0.11 Fix from $1,6002026-05-06 HIGH 7.5 CVE-2026-6918 In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message. Openj9 0.59.0+ Fix from $1,9502026-05-05 CRITICAL 9.1 CVE-2026-2332 In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques out… Jetty 9.4.60 / 10.0.28+ Fix from $2,3002026-04-14 HIGH 7.4 CVE-2026-5795 In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the ini… Jetty 12.0.34 / 12.1.8+ Fix from $1,9502026-04-08 CRITICAL 9.8 CVE-2026-24457 An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's… Openmq after 6.5.1 Fix from $2,3002026-03-05 HIGH 7.5 CVE-2026-1605 In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-E… Jetty 12.0.32 / 12.1.6+ Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2025-11143 The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in system… Jetty 12.0.31 / 12.1.5+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-22886 OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default adminis… Openmq Mitigation only Fix from $2,3002026-03-03 HIGH 8.8 CVE-2026-1699 In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking ou… Theia Website 2026-01-22+ Fix from $1,9502026-01-30 CRITICAL 9.8 CVE-2026-1188 In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was no… Omr 0.8.0+ Fix from $2,3002026-01-29 MEDIUM 6.3 CVE-2026-0648 The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_… Threadx 6.4.5+ Fix from $1,6002026-01-27 HIGH 7.5 CVE-2025-55102 A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of … Threadx Netx Duo 6.4.5.202504+ Fix from $1,9502026-01-27 HIGH 7.0 CVE-2025-55095 The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended… Threadx Usbx after 6.4.2 Fix from $1,9502026-01-27 MEDIUM 5.3 CVE-2026-1002 The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted … Vert.x Web after 5.0.6 Fix from $1,6002026-01-15 CRITICAL 10.0 CVE-2025-67109 Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute command… Cyclone Data Distribution Service 0.10.5+ Fix from $2,3002025-12-23 HIGH 8.1 CVE-2025-14549 In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly h… Omr Patch available Fix from $1,9502025-12-15 MEDIUM 5.3 CVE-2025-10543 In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded i… Paho Mqtt after 1.5.0 Fix from $1,6002025-12-02 HIGH 7.4 CVE-2025-12383 In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, cu… Jersey Mitigation only Fix from $1,9502025-11-18 HIGH 7.5 CVE-2025-11965 In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict… Vert.x 4.5.22 / 5.0.5+ Fix from $1,9502025-10-22 MEDIUM 6.4 CVE-2025-11966 In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into genera… Vert.x 4.5.22 / 5.0.5+ Fix from $1,6002025-10-22 CRITICAL 9.8 CVE-2025-55086 In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extrac… Threadx Netx Duo 6.4.4.202503+ Fix from $2,3002025-10-20 HIGH 7.5 CVE-2025-55085 In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was … Threadx Netx Duo 6.4.4.202503+ Fix from $1,9502025-10-17 CRITICAL 9.1 CVE-2025-55100 In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio10_… Threadx Usbx 6.4.3.202503+ Fix from $2,3002025-10-17 MEDIUM 6.1 CVE-2025-55099 In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_al… Threadx Usbx 6.4.3.202503+ Fix from $1,6002025-10-17