| CVE-2026-9158 | 9.8 | — | — | — | eclipse / 4diac forte | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management int | 79d ago |
| CVE-2026-12605 | 9.6 | — | — | — | eclipse / glassfish | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `g | 30d ago |
| CVE-2026-16441 | 9.6 | — | — | — | eclipse / openj9 | In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method ha | 46d ago |
| CVE-2026-2587 | 9.6 | — | — | — | eclipse / glassfish | A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism | 109d ago |
| CVE-2026-10050 | 9.1 | — | — | — | eclipse / jetty | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. | 32d ago |
| CVE-2026-16439 | 9.1 | — | — | — | eclipse / openj9 | In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. | 46d ago |
| CVE-2026-2586 | 9.1 | — | — | — | eclipse / glassfish | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. | 109d ago |
| CVE-2026-60009 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in | 31d ago |
| CVE-2026-46580 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace wer | 79d ago |
| CVE-2026-44691 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. | 79d ago |
| CVE-2026-44688 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part | 79d ago |
| CVE-2026-58080 | 8.2 | — | — | — | eclipse / milo | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMappe | 32d ago |
| CVE-2026-9561 | 8.2 | — | — | — | eclipse / kura | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative sou | 53d ago |
| CVE-2026-61891 | 7.5 | — | — | — | eclipse / theia | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download e | 31d ago |
| CVE-2026-46581 | 7.5 | — | — | — | eclipse / mojarra | In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize a | 31d ago |
| CVE-2026-12609 | 7.5 | — | — | — | eclipse / theia | In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/host | 31d ago |
| CVE-2026-63252 | 7.5 | — | — | — | eclipse / milo | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial mess | 32d ago |
| CVE-2026-62927 | 7.5 | — | — | — | eclipse / milo | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-spac | 32d ago |
| CVE-2026-61387 | 7.5 | — | — | — | eclipse / milo | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creat | 32d ago |
| CVE-2026-16243 | 7.5 | — | — | — | eclipse / omr | In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of b | 46d ago |
| CVE-2026-15076 | 7.5 | — | — | — | eclipse / vert.x | In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Ecli | 53d ago |
| CVE-2026-15075 | 7.5 | — | — | — | eclipse / vert.x | In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler | 53d ago |
| CVE-2026-10051 | 7.5 | — | — | — | eclipse / jetty | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent re | 53d ago |
| CVE-2024-7708 | 7.5 | — | — | — | eclipse / jetty | For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. | 53d ago |
| CVE-2026-11576 | 7.5 | — | — | — | eclipse / threadx netx duo | The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT pro | 78d ago |
| CVE-2026-60007 | 7.4 | — | — | — | eclipse / milo | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid | 32d ago |