Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-39852Highio.quarkus:quarkus-vertx-http: Quarkus has Authentication/Authorization bypassesCVE-2026-40075Highorg.openmrs.web:openmrs-web: OpenMRS ModuleResourcesServlet has Path Traversal that Leads to Arbitrary File ReadCVE-2026-6501Mediumorg.jopendocument:jOpenDocument: jOpenDocument has an improper restriction of XML external entity reference vulnerabilityCVE-2026-42779Criticalorg.apache.mina:mina-core: Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)CVE-2026-42778Criticalorg.apache.mina:mina-core: Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)CVE-2026-42404Mediumorg.apache.neethi:neethi: Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference APICVE-2026-42403Highorg.apache.neethi:neethi: Apache Neethi does not properly detect circular references in policy definitions.CVE-2026-42402Highorg.apache.neethi:neethi: Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalizationCVE-2026-36766Mediumcom.shopizer:shopizer: Shopizer is vulnerable to Cross-site ScriptingCVE-2026-36767Criticalcom.shopizer:shopizer: Shopizer has a path traversal issueCVE-2026-7500Mediumorg.keycloak:keycloak-services: Keycloak has a Forced Browsing issueGHSA-H8CJ-HPMG-636VHighcom.appsmith:interfaces: appsmith has SQL Injection in FilterDataService via Unsafe DROP TABLE ExecutionCVE-2026-41586Criticalorg.hyperledger.fabric-sdk-java:fabric-sdk-java: fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCECVE-2026-42525Mediumorg.jenkins-ci.plugins:azure-ad: Jenkins Microsoft Entra ID (previously Azure AD) Plugin has an open redirect vulnerabilityCVE-2026-42524Highorg.jenkins-ci.plugins:htmlpublisher: Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper fileCVE-2026-42519Mediumorg.jenkins-ci.plugins:script-security: Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths CVE-2026-42523Criticalorg.jenkins-ci.plugins:git: Jenkins GitHub Plugin has an XSS vulnerabilityCVE-2026-42522Mediumorg.jenkins-ci.plugins:github-branch-source: Jenkins GitHub Branch Source Plugin: Missing permissions check allows attackers to perform a connection testCVE-2026-42521Mediumorg.jenkins-ci.plugins:matrix-auth: Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructorsCVE-2026-42520Highorg.jenkins-ci.plugins:credentials-binding: Jenkins Credentials Binding Plugin has a path traversal vulnerabilityCVE-2026-22741Loworg.springframework:spring-webflux: Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.CVE-2026-22740Mediumorg.springframework:spring-webflux: Spring Framework DoS with Multipart Temp Files in WebFluxCVE-2026-22745Mediumorg.springframework:spring-webflux: Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resourcesCVE-2026-7303Lowcom.xuxueli:xxl-job-admin: xxl-job has a Resource Injection issueCVE-2026-40969Loworg.springframework.grpc:spring-grpc: Spring gRPC AuthenticationException messages are reflected to remote client

Stop the waste.
Protect your environment with Kodem.