33 Total CVEs
33 AI Analyzed
0 CISA KEV
10 Critical

Profile

0% ended up actively exploited 0 of 33 added to CISA KEV
30% rated critical (CVSS 9.0+) 10 critical, 23 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

31 CVEs in the last 12 months

Products

  • Eclipse Theia3
  • Eclipse Milo3
  • Eclipse Arrowhead2
  • GlassFish2
  • Eclipse Vert.x2
  • Theia2
  • Eclipse Kura1
  • Eclipse aeriOS Self-orchestrator1

18 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-33 of 33 CVEs
CVE-2026-9561
Analyzed
8.8
Eclipse Foundation Eclipse Kura

Eclipse Kura versions prior to 5

2026-07-14
CVE-2026-85199
Analyzed
8.8
Eclipse Foundation Eclipse aeriOS Self-orchestrator

Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to c...

2026-09-04
CVE-2026-84736
Analyzed
8.3
Eclipse Foundation Eclipse aeriOS

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certi...

2026-09-04
CVE-2026-82217
Analyzed
8.8
Eclipse Foundation Eclipse Theia

In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the...

2026-09-01
CVE-2026-82180
Analyzed
9.5
Eclipse Foundation Eclipse Arrowhead

Eclipse Arrowhead versions 5.0.0 to 5.2.1 fail to validate X.509 certificate signatures and issuer chains in the MQTT API, allowing unauthenticated at...

2026-09-04
CVE-2026-80515
Analyzed
8.9
Eclipse Foundation Eclipse Arrowhead

In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to app...

2026-09-04
CVE-2026-7412
Analyzed
8.6
Eclipse Foundation Multiple Products

In Eclipse BaSyx Java Server SDK versions prior to 2

2026-05-06
CVE-2026-7411
Analyzed
10
Eclipse Foundation BaSyx Java Server SDK

The Eclipse BaSyx Java Server SDK is vulnerable to path traversal via the Submodel HTTP API, potentially leading to Remote Code Execution.

2026-05-06
CVE-2026-6918
Analyzed
7.5
Eclipse Foundation OpenJ9

In Eclipse Open9J versions 0

2026-05-06
CVE-2026-63252
Analyzed
8.7
Eclipse Foundation Eclipse Milo

In Eclipse Milo versions 0

2026-08-05
CVE-2026-62927
Analyzed
8.7
Eclipse Foundation Eclipse Milo

In Eclipse Milo versions 1

2026-08-05
CVE-2026-60009
Analyzed
8.8
Eclipse Foundation Eclipse Theia

In Eclipse Theia versions up to and including 1

2026-08-06
CVE-2026-58080
Analyzed
8.8
Eclipse Foundation Eclipse Milo

In Eclipse Milo versions 1

2026-08-05
CVE-2026-57898
Analyzed
9
Eclipse Foundation Eclipse BaSyx - Java Server SDK

An unauthenticated arbitrary file write vulnerability in the Eclipse BaSyx Java Server SDK allows remote attackers to write files to the server filesy...

2026-07-14
CVE-2026-2587
Analyzed
9.6
Eclipse Foundation GlassFish

A remote code execution vulnerability in the GlassFish server-side template rendering mechanism allows attackers to execute arbitrary commands via mal...

2026-05-20
CVE-2026-2586
Analyzed
9.1
Eclipse Foundation GlassFish

An authenticated remote code execution vulnerability exists in the GlassFish Administration Console, allowing users with console access to execute arb...

2026-05-20
CVE-2026-22886
Analyzed
9.8
Eclipse Foundation imqbrokerd

OpenMQ's imqbrokerd service uses a default administrative account (admin/admin) and fails to enforce password changes, allowing remote attackers full...

2026-03-04
CVE-2026-19884
Analyzed
8.4
Eclipse Foundation Eclipse Theia

In Eclipse Theia versions up to and including 1

2026-08-16
CVE-2026-18353
Analyzed
8.8
Eclipse Foundation Eclipse CSI - PIA

PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlpa...

2026-07-30
CVE-2026-1699
Analyzed
10
Eclipse Foundation Multiple Products

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out...

2026-01-31
CVE-2026-1605
Analyzed
7.5
Eclipse Foundation Multiple Products

In Eclipse Jetty, versions 12

2026-03-07
CVE-2026-15803
Analyzed
8.7
Eclipse Foundation Eclipse RDF4J

In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data...

2026-08-14
CVE-2026-15704
Analyzed
9.8
Eclipse Foundation Eclipse BaSyx Go Components

Eclipse BaSyx Go Components contains an authorization bypass vulnerability where inconsistent trailing-slash handling allows attackers to circumvent A...

2026-07-24
CVE-2026-15076
Analyzed
8.2
Eclipse Foundation Eclipse Vert.x

In versions up to and including 4

2026-07-14
CVE-2026-15075
Analyzed
8.2
Eclipse Foundation Eclipse Vert.x

In Eclipse Vert

2026-07-14
CVE-2026-14336
Analyzed
8.2
Eclipse Foundation PIA (OIDC issuer allowlist)

PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer

2026-07-03
CVE-2026-10055
Analyzed
8.5
Eclipse Foundation Theia

In Eclipse Theia since version 1

2026-07-03
CVE-2026-10054
Analyzed
8.8
Eclipse Foundation Theia

In affected versions of Eclipse Theia (1

2026-07-03
CVE-2026-10050
Analyzed
8.7
Eclipse Foundation Eclipse Jetty

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes

2026-08-04
CVE-2026-0648
Analyzed
7.8
Eclipse Foundation Multiple Products

The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_o...

2026-01-28
CVE-2025-2515
Analyzed
7.2
Eclipse Foundation Multiple Products

A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS

2025-12-26
CVE-2024-9408
Analyzed
9.8
Eclipse Foundation Multiple Products

In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.

2025-07-16
CVE-2024-9342
Analyzed
9.8
Eclipse Foundation Multiple Products

In Eclipse GlassFish version 7.0.16 or earlier it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed l...

2025-07-16