Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-24880Highorg.apache.tomcat:tomcat-coyote: Apache Tomcat has an HTTP Request/Response Smuggling vulnerabilityCVE-2026-29146Highorg.apache.tomcat:tomcat: Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptorCVE-2026-34020Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings CVE-2026-40046Mediumorg.apache.activemq:apache-activemq: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or WraparoundCVE-2026-33266Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings Uses Hard-coded Cryptographic KeyCVE-2026-33005Mediumorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerabilityCVE-2025-62188Highorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler vulnerable to sensitive information disclosureCVE-2026-40180Mediumio.quarkiverse.openapi.generator:quarkus-openapi-generator: quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper classCVE-2026-33229Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting APICVE-2026-35583Mediumgov.nsa.emissary:emissary: Emissary has a Path Traversal via Blacklist Bypass in Configuration APICVE-2026-35581Highgov.nsa.emissary:emissary: Emissary has a Command Injection via PLACE_NAME Configuration in ExecutrixCVE-2026-35580Criticalgov.nsa.emissary:emissary: Emissary has GitHub Actions Shell Injection via Workflow InputsCVE-2026-5739Mediumtech.powerjob:powerjob-server-starter: PowerJob's GroovyEvaluator.evaluate endpoint vulnerable to code injectionCVE-2026-5736Mediumtech.powerjob:powerjob-server-starter: PowerJob vulnerable to SQL injectionCVE-2026-35571Mediumgov.nsa.emissary:emissary: Emissary has Stored XSS via Navigation Template Link InjectionCVE-2026-35568Highio.modelcontextprotocol.sdk:mcp-core: Java-SDK has a DNS Rebinding VulnerabilityCVE-2026-32588Loworg.apache.cassandra:cassandra-all: Apache Cassandra has an authenticated DoS over CQLCVE-2026-27315Mediumorg.apache.cassandra:cassandra-all: Apache Cassandra has sensitive Information Leak in cqlshCVE-2026-27314Highorg.apache.cassandra:cassandra-all: Apache Cassandra is vulnerable to privilege escalation in an mTLS environment using MutualTlsAuthenticatorCVE-2026-33439Criticalorg.openidentityplatform.openam:openam: OpenIdentityPlatform OpenAM: Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAMCVE-2026-35554Highorg.apache.kafka:kafka-clients: Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race ConditionCVE-2026-33227Mediumorg.apache.activemq:activemq-client: Apache ActiveMQ: Improper validation and restriction of a classpath path nameCVE-2026-34197Highorg.apache.activemq:activemq-broker: Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeansCVE-2026-37977Loworg.keycloak:keycloak-services: Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claimGHSA-2M67-WJPJ-XHG9Hightools.jackson.core:jackson-core: Jackson Core: Document length constraint bypass in blocking, async, and DataInput parsers

Stop the waste.
Protect your environment with Kodem.