Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-59059Criticalorg.apache.ranger:ranger-plugins-common: Apache Ranger has a Code Injection vulnerabilityCVE-2025-59060Mediumorg.apache.ranger:ranger-nifi-registry-plugin: Apache Ranger Vulnerable to Improper Validation of Certificate with Host MismatchCVE-2026-28338Mediumnet.sourceforge.pmd:pmd-core: PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messagesGHSA-72HV-8253-57QQMediumtools.jackson.core:jackson-core: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS ConditionCVE-2026-28208Mediumcom.github.junrar:junrar: Junrar has an arbitrary file write due to backslash Path Traversal bypass in LocalFolderExtractor on Linux/UnixCVE-2025-12150Loworg.keycloak:keycloak-services: Keycloak REST Services has a WebAuthn Attestation Statement Verification BypassCVE-2026-0871Mediumorg.keycloak:keycloak-server-spi-private: Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged…CVE-2026-3293Lownet.snowflake:snowflake-jdbc: Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlannerCVE-2026-3269Lowcom.github.psi-probe:psi-probe-core: PSI Probe: Broken access control can lead to DoS CVE-2026-3270Lowcom.github.psi-probe:psi-probe-core: PSI Probe vulnerable to Server-Side Request ForgeryCVE-2026-27830Highcom.mchange:c3p0: c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString propertyCVE-2026-27727Highcom.mchange:mchange-commons-java: mchange-commons-java: Remote Code Execution via JNDI Reference ResolutionCVE-2026-23552Criticalorg.apache.camel:camel-keycloak: Apache Camel: KeycloakSecurityPolicy does not validate issuer of JWT tokens against configured realmCVE-2026-25747Highorg.apache.camel:camel-leveldb: Apache Camel Deserializes Untrusted Data in its LevelDB ComponentCVE-2025-13590Criticalorg.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl: carbon-apimgt does not properly restrict uploaded filesCVE-2026-2733Loworg.keycloak:keycloak-services: Keycloak: Missing Check on Disabled Client for Docker Registry ProtocolCVE-2026-2666Lownet.mingsoft:ms-mcms: mingSoft MCMS does not properly restrict file uploadsCVE-2026-27100Mediumorg.jenkins-ci.main:jenkins-core: Jenkins has a build information disclosure vulnerability through Run Parameter CVE-2026-27099Highorg.jenkins-ci.main:jenkins-core: Jenkins has a stored XSS vulnerability in node offline cause descriptionCVE-2026-24734Highorg.apache.tomcat:tomcat-coyote: Apache Tomcat has an Improper Input Validation vulnerabilityCVE-2026-24733Loworg.apache.tomcat:tomcat-coyote: Apache Tomcat - Security constraint bypass with HTTP/0.9CVE-2025-66614Mediumorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat - Client certificate verification bypassCVE-2026-25903Highorg.apache.nifi:nifi-web-api: Apache NiFi: Missing Authorization of Restricted Permissions for Component UpdatesCVE-2025-23368Highorg.wildfly.core:wildfly-elytron-integration: Wildfly Elytron integration susceptible to brute force attacks via CLICVE-2025-33042Mediumorg.apache.avro:avro-compiler: Apache Avro Java SDK is Vulnerable to Code Injection

Stop the waste.
Protect your environment with Kodem.