CRITICAL9.8CVE-2014-3600Improper Restriction of XML External Entity Reference in Apache ActiveMQ >= 5.0.0, < 5.10.1
HIGH8.8CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass from 0, < 5.19.7
HIGH8.1CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector from 0, < 5.19.7
MEDIUM6.5Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues
from 0, < 5.19.6
MEDIUM5.9Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)
from 0, < 5.19.7
MEDIUM4.3Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath Directory
from 0, < 5.19.3
—Improper Input Validation in Apache ActiveMQ
>= 5.0.0, < 5.10.2
—Improper Authentication in Apache WSS4J
>= 5.0.0, < 5.10.1