Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12605 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12605)
SSRF in ssrf (CVE-2026-12605). Successful exploitation can lead to full system takeover. Exploitable via ``gfresttoken``.
|
| CVE-2026-61891 |
|
Path Traversal in eclipse (CVE-2026-61891)
path traversal in eclipse (CVE-2026-61891). Confidential information can be exposed externally. Exploitable via `GET /file`.
|
| CVE-2026-46581 |
|
Path Traversal in eclipse (CVE-2026-46581)
path traversal in eclipse (CVE-2026-46581). Confidential information can be exposed externally. Exploitable via ``DefaultFaceletFactory``.
|
| CVE-2026-14574 |
|
Vulnerability in eclipse (CVE-2026-14574)
vulnerability in eclipse (CVE-2026-14574). Data can be tampered with by attackers. Exploitable via ``PreferenceUtils.merge``.
|
| CVE-2026-14304 |
|
XXE (XML External Entity) in eclipse (CVE-2026-14304)
vulnerability in eclipse (CVE-2026-14304). Confidential information can be exposed externally.
|
| CVE-2026-12609 |
|
Path Traversal in eclipse (CVE-2026-12609)
path traversal in eclipse (CVE-2026-12609). Confidential information can be exposed externally.
|
| CVE-2026-60009 |
|
Path Traversal in eclipse (CVE-2026-60009)
path traversal in eclipse (CVE-2026-60009). Successful exploitation can lead to full system takeover. Exploitable via `POST /file-upload`.
|
| CVE-2026-61387 |
|
Vulnerability in eclipse (CVE-2026-61387)
vulnerability in eclipse (CVE-2026-61387). Risk of unauthorized operations or information disclosure. Exploitable via ``CreateMonitoredItems``.
|
| CVE-2026-58080 |
|
Vulnerability in eclipse (CVE-2026-58080)
vulnerability in eclipse (CVE-2026-58080). Data can be tampered with by attackers. Exploitable via ``RoleMapper``.
|
| CVE-2026-62927 |
|
Authorization Flaw in eclipse (CVE-2026-62927)
vulnerability in eclipse (CVE-2026-62927). Data can be tampered with by attackers.
|
| CVE-2026-63248 |
|
Vulnerability in eclipse (CVE-2026-63248)
vulnerability in eclipse (CVE-2026-63248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60007 |
|
Vulnerability in eclipse (CVE-2026-60007)
vulnerability in eclipse (CVE-2026-60007). Confidential information can be exposed externally. Exploitable via ``Basic128Rsa15``.
|
| CVE-2026-63252 |
|
Vulnerability in eclipse (CVE-2026-63252)
vulnerability in eclipse (CVE-2026-63252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10050 |
|
Vulnerability in org.eclipse.jetty:jetty-security (CVE-2026-10050)
vulnerability in org.eclipse.jetty:jetty-security (CVE-2026-10050). Confidential information can be exposed externally. Mitigation: upgrade to `12.1.10` or later.
|
| CVE-2026-16441 |
|
Vulnerability in eclipse (CVE-2026-16441)
vulnerability in eclipse (CVE-2026-16441). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16243 |
|
Out-of-Bounds Read in eclipse (CVE-2026-16243)
vulnerability in eclipse (CVE-2026-16243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16439 |
|
Vulnerability in eclipse (CVE-2026-16439)
vulnerability in eclipse (CVE-2026-16439). Data can be tampered with by attackers.
|
| CVE-2026-16454 |
|
Vulnerability in privilege-escalation (CVE-2026-16454)
vulnerability in privilege-escalation (CVE-2026-16454). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9561 |
|
Vulnerability in dos (CVE-2026-9561)
vulnerability in dos (CVE-2026-9561). Data can be tampered with by attackers.
|
| CVE-2026-13699 |
|
Vulnerability in eclipse (CVE-2026-13699)
vulnerability in eclipse (CVE-2026-13699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15076 |
|
Vulnerability in eclipse (CVE-2026-15076)
vulnerability in eclipse (CVE-2026-15076). Confidential information can be exposed externally.
|
| CVE-2026-12606 |
|
Vulnerability in eclipse (CVE-2026-12606)
vulnerability in eclipse (CVE-2026-12606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8384 |
|
Vulnerability in org.eclipse.jetty:jetty-util (CVE-2026-8384)
vulnerability in org.eclipse.jetty:jetty-util (CVE-2026-8384). Risk of unauthorized operations or information disclosure. Exploitable via `GET /admin/secret`. Mitigation: upgrade to `12.1.9` or later.
|
| CVE-2026-6790 |
|
Vulnerability in org.eclipse.jetty:jetty-server (CVE-2026-6790)
vulnerability in org.eclipse.jetty:jetty-server (CVE-2026-6790). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `12.1.9` or later.
|
| CVE-2026-15075 |
|
Information Disclosure in eclipse (CVE-2026-15075)
vulnerability in eclipse (CVE-2026-15075). Confidential information can be exposed externally.
|
| CVE-2024-7708 |
|
Vulnerability in org.eclipse.jetty:jetty-server (CVE-2024-7708)
vulnerability in org.eclipse.jetty:jetty-server (CVE-2024-7708). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.23` or later.
|
| CVE-2026-10051 |
|
Information Disclosure in org.eclipse.jetty:jetty-server (CVE-2026-10051)
vulnerability in org.eclipse.jetty:jetty-server (CVE-2026-10051). Confidential information can be exposed externally. Exploitable via `POST /upload`. Mitigation: upgrade to `12.1.10` or later.
|
| CVE-2026-13323 |
|
Cross-Site Scripting (XSS) in eclipse (CVE-2026-13323)
cross-site scripting in eclipse (CVE-2026-13323). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4983 |
|
Cross-Site Scripting (XSS) in eclipse (CVE-2026-4983)
cross-site scripting in eclipse (CVE-2026-4983). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11576 |
|
Vulnerability in eclipse (CVE-2026-11576)
vulnerability in eclipse (CVE-2026-11576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44691 |
|
Vulnerability in @theia/debug (CVE-2026-44691)
vulnerability in @theia/debug (CVE-2026-44691). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.69.0` or later.
|
| CVE-2026-46580 |
|
Vulnerability in @theia/ai-chat-ui (CVE-2026-46580)
vulnerability in @theia/ai-chat-ui (CVE-2026-46580). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.71.0` or later.
|
| CVE-2026-44688 |
|
Vulnerability in @theia/ai-chat-ui (CVE-2026-44688)
vulnerability in @theia/ai-chat-ui (CVE-2026-44688). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.71.0` or later.
|
| CVE-2026-22551 |
|
Vulnerability in @theia/ai-chat-ui (CVE-2026-22551)
vulnerability in @theia/ai-chat-ui (CVE-2026-22551). Confidential information can be exposed externally. Mitigation: upgrade to `1.71.0` or later.
|
| CVE-2026-9158 |
|
Use-After-Free in eclipse (CVE-2026-9158)
vulnerability in eclipse (CVE-2026-9158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2586 |
|
Code Injection in org.glassfish.main.admingui:console-common (CVE-2026-2586)
code injection in org.glassfish.main.admingui:console-common (CVE-2026-2586). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.2` or later.
|
| CVE-2026-2587 |
|
Vulnerability in org.glassfish.main.admingui:admingui (CVE-2026-2587)
vulnerability in org.glassfish.main.admingui:admingui (CVE-2026-2587). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.2` or later.
|
| CVE-2026-6860 |
|
Vulnerability in io.vertx:vertx-core (CVE-2026-6860)
vulnerability in io.vertx:vertx-core (CVE-2026-6860). Risk of unauthorized operations or information disclosure. Exploitable via ``SslContext``. Mitigation: upgrade to `5.0.12` or later.
|
| CVE-2026-6918 |
|
Out-of-Bounds Read in eclipse (CVE-2026-6918)
vulnerability in eclipse (CVE-2026-6918). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2332 |
|
Vulnerability in org.eclipse.jetty:jetty-http (CVE-2026-2332)
vulnerability in org.eclipse.jetty:jetty-http (CVE-2026-2332). Confidential information can be exposed externally. Exploitable via `GET /smuggled`. Mitigation: upgrade to `11.0.29` or later.
|
| CVE-2026-5795 |
|
Vulnerability in privilege-escalation (CVE-2026-5795)
vulnerability in privilege-escalation (CVE-2026-5795). Confidential information can be exposed externally.
|
| CVE-2026-24457 |
|
Path Traversal in eclipse (CVE-2026-24457)
path traversal in eclipse (CVE-2026-24457). Confidential information can be exposed externally.
|
| CVE-2026-1605 |
|
Vulnerability in eclipse (CVE-2026-1605)
vulnerability in eclipse (CVE-2026-1605). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-67109 |
|
Vulnerability in eclipse (CVE-2025-67109)
vulnerability in eclipse (CVE-2025-67109). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7962 |
|
Vulnerability in eclipse (CVE-2025-7962)
vulnerability in eclipse (CVE-2025-7962). Data can be tampered with by attackers.
|
| CVE-2024-9342 |
|
Vulnerability in eclipse (CVE-2024-9342)
vulnerability in eclipse (CVE-2024-9342). Successful exploitation can lead to full system takeover.
|
| CVE-2023-44487 KEV |
|
[KEV] Vulnerability in Ietf golang.org/x/net (CVE-2023-44487)
vulnerability in Ietf golang.org/x/net (CVE-2023-44487). Risk of unauthorized operations or information disclosure. Exploitable via ``Channel``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.17.0` or later.
|
| CVE-2022-2712 |
|
Path Traversal in path-traversal (CVE-2022-2712)
path traversal in path-traversal (CVE-2022-2712). Confidential information can be exposed externally.
|
| CVE-2021-34432 |
|
Vulnerability in eclipse (CVE-2021-34432)
vulnerability in eclipse (CVE-2021-34432). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-7650 |
|
Authentication Bypass in eclipse (CVE-2017-7650)
authentication bypass in eclipse (CVE-2017-7650). Confidential information can be exposed externally.
|