Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55848Highorg.mapfish.print:print-lib: MapFish Print has XXE that allows reading arbitrary files of certain typesCVE-2026-55867Mediumorg.graylog2:graylog2-server: Graylog token revocation endpoint allows authenticated users to delete other users’ access tokensCVE-2026-55841Highorg.graylog2:graylog2-server: Fortigate syslog message parser can be exploited to modify or delete fields from the original messageCVE-2026-55673Highcom.powsybl:powsybl-computation-local: PowSyBl Core has Command Injection in LocalCommandExecutor-sCVE-2026-55175Highio.spinnaker.rosco:rosco-manifests: Spinnaker: Improper yaml processing on kustomize bake operationsCVE-2026-55425Mediumorg.graylog2:graylog2-server: Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fieldsCVE-2026-55566Mediumorg.yamcs:yamcs-core: Yamcs has DOM XSS in Extension RoutingCVE-2026-55565Criticalorg.yamcs:yamcs-core: Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)CVE-2026-55559Criticalorg.yamcs:yamcs-core: Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)CVE-2026-55552Highorg.yamcs:yamcs-core: Yamcs has Unauthenticated Directory TraversalCVE-2026-55549Mediumorg.yamcs:yamcs-core: Yamcs has Reflected XSS in the URL of the Authorize EndpointCVE-2026-55548Mediumorg.yamcs:yamcs-core: Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packetsCVE-2026-55547Mediumorg.yamcs:yamcs-core: Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security…CVE-2026-55545Mediumorg.yamcs:yamcs-core: Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforceCVE-2026-55521Highorg.yamcs:yamcs-core: Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilitiesCVE-2026-55511Criticalorg.yamcs:yamcs-core: Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`CVE-2026-55688Mediumorg.asynchttpclient:async-http-client: AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStoreCVE-2026-54550Highorg.codehaus.izpack:izpack-installer: IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entriesCVE-2026-54556Highorg.http4s:http4s-ember-core_2.12: http4s has HTTP/2 Denial of Service with Ember BackendCVE-2026-65905Criticalorg.apache.tomcat:tomcat: Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerabilityCVE-2026-65182Criticalorg.apache.tomcat:tomcat: Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerabilityCVE-2026-68525Criticalorg.apache.tomcat:tomcat: Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerabilityCVE-2026-54050Mediumorg.sakaiproject.profile2:profile2-api: Sakai Profile Image Deletion has an IDORCVE-2026-54049Highorg.sakaiproject.conversations:sakai-conversations-impl: Sakai Conversations has a Stored XSS IssueCVE-2026-78329Criticalorg.apache.camel:camel-undertow: Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow…

Stop the waste.
Protect your environment with Kodem.