Where
-Infinity
0

Oracle GlassFish Administration ConsoleCode Injection

Risk 72
Severity
9.1
First published (updated )

Eclipse GlassFishA critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rend…

Risk 80
Severity
9.6
First published (updated )

maven/io.vertx:vertx-coreA TCP client can perform a TLS handshake and present the server name extension with a server name th…

Risk 23
Severity
6.9
EPSS
0.03%
First published (updated )

Eclipse BaSyx Java Server SDKSSRF

Risk 34
Severity
8.6
EPSS
0.03%
First published (updated )

Eclipse BaSyx Java Server SDKPath Traversal

Risk 61
Severity
10
EPSS
0.13%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Eclipse Openj9In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by…

Risk 33
Severity
8.7
EPSS
0.04%
First published (updated )

Eclipse Equinox OSGiEclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution

Risk 86
Severity
9.3
First published (updated )

Eclipse Eclipse Equinox OSGiEclipse Equinox OSGi 3.7.2 Remote Code Execution via Console

Risk 86
Severity
9.3
First published (updated )

Eclipse JettyIn Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are u…

Risk 33
Severity
7
First published (updated )

Eclipse JettyHTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Eclipse JettyIn Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two Th…

Risk 33
Severity
7
First published (updated )

maven/org.eclipse.jetty.ee10:jetty-ee10In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two Th…

Risk 41
Severity
7.4
EPSS
0.02%
First published (updated )

Eclipse Open Message QueuePath Traversal

Risk 86
Severity
9.8
First published (updated )

Eclipse JettyIn Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerabili…

Risk 33
Severity
7
First published (updated )

Eclipse JettyIn Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerabili…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/org.eclipse.jetty:jetty-httpInput Validation

Risk 40
Severity
6.5
First published (updated )

Oracle OpenMQOpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. …

Risk 86
Severity
9.8
First published (updated )

Eclipse theiaIn the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml u…

Risk 87
Severity
10
First published (updated )

Eclipse OMRBuffer Overflow

Risk 86
Severity
6.9
First published (updated )

Eclipse ThreadXThe vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in t…

Risk 65
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Eclipse Threadx UsbxThe function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB ma…

Risk 63
Severity
7
First published (updated )

Eclipse ThreadX NetX DuoA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX…

Risk 47
Severity
8.7
First published (updated )

maven/io.vertx:vertx-coreEclipse Vert.x Web static handler file access denial

Risk 31
Severity
6.9
EPSS
0.05%
First published (updated )

Eclipse Cyclone DDSImproper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers…

Risk 87
Severity
10
First published (updated )

Eclipse OMROMR on Z processors Exposing a possible buffer over-read problem

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Eclipse Paho Go MQTTIn Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, pass…

Risk 29
Severity
6.3
First published (updated )

Eclipse JerseyRace Condition allows Bypass of Trust Restrictions

Risk 61
Severity
9.4
First published (updated )

Eclipse Vert.xIn Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for res…

Risk 43
Severity
7.5
First published (updated )

Eclipse Vert.xXSS, CSRF

Risk 39
Severity
6.4
First published (updated )

Eclipse Foundation NetXDuoIn NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the …

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203