Vulnerabilities
Summary — last 7 days
New vulnerabilities2,635▼ 213 vs. last week
Critical / high1,376▲ 145 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
357 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.8) | 0.62% | — | Eclipse TheiaAI | 8/31/2026 | 9/1/2026 | In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path such as ../.bashrc, an absolute path,… | |
| Deferred | Critical (9.1) | 0.37% | — | Eclipse LYOAI | 8/28/2026 | 9/1/2026 | In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilter`, are vulnerable. An attacked can create a provisional trusted… | |
| Deferred | Medium (6) | 0.47% | — | Eclipse Sw360AI | 8/27/2026 | 9/1/2026 | In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path traversal. The immediate workaround is to… | |
| Deferred | Critical (9.3) | 0.53% | — | Cudy Wr3000AIEclipse MosquittoAI | 8/19/2026 | 9/9/2026 | Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to… | |
| Deferred | Medium (5.7) | 0.24% | — | Eclipse Openjava9AI | 8/19/2026 | 9/1/2026 | In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault. | |
| Awaiting Analysis | High (8.4) | 0.19% | — | Eclipse TheiaAI | 8/14/2026 | 8/18/2026 | In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own `@theia/git` extension and the builtin VS… | |
| Awaiting Analysis | Medium (6.9) | 0.52% | — | Signify Philips HUE Bridge PROAIEclipse MosquittoAI | 8/13/2026 | 8/26/2026 | The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010. | |
| Awaiting Analysis | High (8.7) | 0.47% | — | Eclipse Rdf4jAI | 8/12/2026 | 8/18/2026 | In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an incomplete fix for CVE-2018-1000644: the… | |
| Analyzed | Critical (9.6) | 0.43% | — | Eclipse Glassfish | 8/6/2026 | 8/10/2026 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires. | |
| Analyzed | High (7.5) | 0.53% | — | Eclipse Theia | 8/5/2026 | 8/7/2026 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In… | |
| Analyzed | High (7.5) | 0.56% | — | Eclipse Mojarra | 8/5/2026 | 8/10/2026 | In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could… | |
| Analyzed | High (8.8) | 0.44% | — | Eclipse Theia | 8/5/2026 | 8/7/2026 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement… | |
| Analyzed | Medium (5.7) | 0.40% | — | Eclipse Theia | 8/5/2026 | 8/7/2026 | In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function is invoked by `PreferenceServiceImpl.doResolve` for every… | |
| Analyzed | Medium (4.6) | 0.23% | — | Eclipse Accessibility Tools FrameworkSoumu Michecker | 8/5/2026 | 8/10/2026 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party… | |
| Analyzed | High (7.5) | 0.52% | — | Eclipse Theia | 8/5/2026 | 8/7/2026 | In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that the resolved path stays within the plugin's directory. An… | |
| Analyzed | High (8.7) | 0.58% | — | Eclipse Milo | 8/4/2026 | 8/5/2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server. | |
| Analyzed | Medium (6.9) | 0.26% | — | Eclipse Milo | 8/4/2026 | 8/5/2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other… | |
| Analyzed | High (8.7) | 0.42% | — | Eclipse Milo | 8/4/2026 | 8/5/2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method. | |
| Analyzed | Medium (6.9) | 0.62% | — | Eclipse Milo | 8/4/2026 | 8/5/2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can trigger a `StackOverflowError` during… | |
| Analyzed | Critical (9.1) | 0.55% | — | Eclipse Milo | 8/4/2026 | 8/5/2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession`… | |
| Analyzed | High (8.8) | 0.38% | — | Eclipse Milo | 8/4/2026 | 8/5/2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing… | |
| Analyzed | High (8.7) | 0.63% | — | Eclipse Jetty | 8/4/2026 | 8/8/2026 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot… | |
| Awaiting Analysis | High (8.8) | 0.41% | — | Eclipse PIAAI | 7/30/2026 | 7/30/2026 | PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlparse` before performing OIDC discovery with `requests`. Because `urlparse` and `requests`/`urllib3` parse an authority string containing a backslash (e.g.… | |
| Awaiting Analysis | Critical (9.8) | 0.65% | — | Eclipse Basyx GO ComponentsAI | 7/24/2026 | 7/30/2026 | In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such… | |
| Analyzed | Medium (6.9) | 0.53% | — | Eclipse Openj9 | 7/21/2026 | 8/18/2026 | In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method. |