VYPR

Vendor CVEs

Eclipse

All CVEs

356 total · sorted by risk
  • CVE-2021-28169MedJun 9, 2021
    risk 0.41cvss 5.3epss 0.78

    For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml…

  • CVE-2025-55099MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing a descriptor with attacker-controlled frequency fields.

  • CVE-2025-55098MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_device_type_get() when parsing a descriptor of an USB audio device.

  • CVE-2025-55097MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_streaming_sampling_get() when parsing a descriptor of an USB streaming device.

  • CVE-2025-55096MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_hid_report_descriptor_get()  when parsing a descriptor of an USB HID device.

  • CVE-2024-9343MedJul 16, 2025
    risk 0.40cvss 6.1epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

  • CVE-2024-10029MedJul 16, 2025
    risk 0.40cvss 6.1epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.

  • CVE-2021-28161MedMar 12, 2021
    risk 0.40cvss 6.1epss 0.01

    In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.

  • CVE-2019-17632MedNov 25, 2019
    risk 0.40cvss 6.1epss 0.02

    In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

  • CVE-2009-5046MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.02

    JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

  • CVE-2009-5049MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.02

    WebApp JSP Snoop page XSS in jetty though 6.1.21.

  • CVE-2009-5048MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.02

    Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.

  • CVE-2019-11776MedAug 9, 2019
    risk 0.40cvss 6.1epss 0.01

    In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.

  • CVE-2019-10241MedApr 22, 2019
    risk 0.40cvss 6.1epss 0.10

    In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory…

  • CVE-2023-3592MedOct 2, 2023
    risk 0.38cvss 5.8epss 0.01

    In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.

  • CVE-2023-0809MedOct 2, 2023
    risk 0.38cvss 5.8epss 0.01

    In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.

  • CVE-2026-85201MedSep 7, 2026
    risk 0.37cvss —epss 0.00

    In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length,…

  • CVE-2024-4536MedMay 7, 2024
    risk 0.37cvss 6.8epss 0.00

    In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from the vault. In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, we have…

  • CVE-2026-14304MedAug 5, 2026
    risk 0.36cvss 5.5epss 0.00

    In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this…

  • CVE-2025-55079MedOct 15, 2025
    risk 0.36cvss 5.5epss 0.00

    In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't performed, allowing, as a result, to obtain a thread with higher priority than expected and causing a possible denial of service.

  • CVE-2025-55078MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check wasn't verifying whether the pointer is outside the module…

  • CVE-2020-6950MedJun 2, 2021
    risk 0.36cvss 6.5epss 0.10

    Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

  • CVE-2017-9868MedJun 25, 2017
    risk 0.36cvss 5.5epss 0.00

    In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.

  • CVE-2026-63248MedAug 4, 2026
    risk 0.35cvss 6.5epss 0.00

    In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it…

  • CVE-2026-22551MedJun 18, 2026
    risk 0.35cvss 6.5epss 0.00

    In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to…

  • CVE-2024-10032MedJul 16, 2025
    risk 0.35cvss 5.4epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

  • CVE-2024-10031MedJul 16, 2025
    risk 0.35cvss 5.4epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.

  • CVE-2025-4949MedMay 21, 2025
    risk 0.35cvss 5.3epss 0.01

    In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML…

  • CVE-2024-3935MedOct 30, 2024
    risk 0.35cvss 6.5epss 0.01

    In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted…

  • CVE-2024-9823MedOct 14, 2024
    risk 0.35cvss 5.3epss 0.01

    There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the…

  • CVE-2024-5165MedMay 23, 2024
    risk 0.35cvss 6.5epss 0.01

    In Eclipse Ditto versions 3.0.0 to 3.5.5, the user input of several input fields of the Eclipse Ditto Explorer User Interface https://eclipse.dev/ditto/user-interface.html was not properly neutralized and thus vulnerable to both Reflected and Stored XSS (Cross Site Scripting).…

  • CVE-2024-1023MedMar 27, 2024
    risk 0.35cvss 6.5epss 0.02

    A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate…

  • CVE-2023-40167MedSep 15, 2023
    risk 0.35cvss 5.3epss 0.01

    Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RFC and other servers routinely…

  • CVE-2023-41034MedAug 31, 2023
    risk 0.35cvss 6.5epss 0.01

    Eclipse Leshan is a device management server and client Java implementation. In affected versions DDFFileParser` and `DefaultDDFFileValidator` (and so `ObjectLoader`) are vulnerable to `XXE Attacks`. A DDF file is a LWM2M format used to store LWM2M object description. Leshan…

  • CVE-2023-32081MedMay 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.0 until 4.4.2, a Vert.x STOMP server processes client STOMP frames without checking that the client send an initial CONNECT frame…

  • CVE-2022-2712MedJan 27, 2023
    risk 0.35cvss 6.5epss 0.01

    In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration…

  • CVE-2022-25370MedSep 2, 2022
    risk 0.35cvss 5.4epss 0.03

    Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142), an…

  • CVE-2021-34434MedAug 30, 2021
    risk 0.35cvss 5.3epss 0.01

    In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.

  • CVE-2019-17639MedJul 15, 2020
    risk 0.35cvss 5.3epss 0.01

    In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an…

  • CVE-2019-18212MedOct 23, 2019
    risk 0.35cvss 6.5epss 0.03

    XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal.

  • CVE-2019-11779MedSep 19, 2019
    risk 0.35cvss 6.5epss 0.03

    In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.

  • CVE-2019-11778MedSep 18, 2019
    risk 0.35cvss 5.4epss 0.01

    If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, sets a session expiry interval, and the will delay interval is set longer than the session expiry interval, then a use after free…

  • CVE-2019-10247MedApr 22, 2019
    risk 0.35cvss 5.3epss 0.06

    In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a…

  • CVE-2019-10246MedApr 22, 2019
    risk 0.35cvss 5.3epss 0.04

    In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information…

  • CVE-2019-10243MedApr 9, 2019
    risk 0.35cvss 5.3epss 0.02

    In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura.

  • CVE-2019-10242MedApr 9, 2019
    risk 0.35cvss 5.3epss 0.02

    In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.

  • CVE-2018-12541MedOct 10, 2018
    risk 0.35cvss 6.5epss 0.03

    In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an…

  • CVE-2018-12536MedJun 27, 2018
    risk 0.35cvss 5.3epss 0.04

    In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a…

  • CVE-2017-7653MedJun 5, 2018
    risk 0.35cvss 5.3epss 0.01

    The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject invalid UTF-8 strings to disconnect themselves from the broker by sending a topic string which is not valid UTF-8, and…

  • CVE-2026-86590MedSep 8, 2026
    risk 0.34cvss —epss 0.00

    In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery…

Page 5 of 8