Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-26000Mediumorg.xwiki.platform:xwiki-platform-web: XWiki vulnerable to click-jacking through CSS injection in commentsCVE-2026-26010Highorg.open-metadata:openmetadata-sdk: Leaky JWTs in OpenMetadata exposing highly-privileged bot usersCVE-2026-23906Criticalorg.apache.druid.extensions:druid-basic-security: Apache Druid Vulnerable to Authentication BypassCVE-2026-23901Loworg.apache.shiro:shiro-core: Apache Shiro Affected by an Observable Timing Discrepancy VulnerabilityCVE-2025-11537Mediumorg.keycloak:keycloak-quarkus-server: Keycloak logs sensitive headersCVE-2025-14778Mediumorg.keycloak:keycloak-services: Keycloak Affected by Broken Access Control Vulnerability in the UserManagedPermissionServiceCVE-2026-1486Highorg.keycloak:keycloak-services: Keycloak fails to verify if an Identity Provider (IdP) is enabled before issuing tokensCVE-2026-1529Highorg.keycloak:keycloak-services: Keycloak affected by improper invitation token validationCVE-2026-23903Mediumorg.apache.shiro:shiro-spring: Apache Shiro has an Authentication BypassCVE-2026-1337Loworg.neo4j:neo4j: Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query logCVE-2026-1622Mediumorg.neo4j:neo4j: Neo4j Enterprise and Community vulnerable to a potential information disclosureCVE-2026-23794Mediumorg.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui: Apache Syncope: Reflected XSS on Enduser LoginCVE-2026-23795Mediumorg.apache.syncope.client.idrepo:syncope-client-idrepo-console: Apache Syncope: Console XXE on Keymaster parametersCVE-2026-25526Criticalcom.hubspot.jinjava:jinjava: JinJava Bypass through ForTag leads to Arbitrary Java ExecutionCVE-2026-1770Mediumorg.craftercms:craftercms: Crafter CMS has Improper Control of Dynamically-Managed Code ResourcesCVE-2024-5986Criticalai.h2o:h2o-core: H2O has an External Control of File Name or Path vulnerabilityCVE-2026-1518Loworg.keycloak:keycloak-parent: Keycloak Server-Side Request Forgery (SSRF) vulnerabilityCVE-2025-13881Loworg.keycloak:keycloak-services: Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributesCVE-2024-4027Highio.undertow:undertow-core: Undertow Servlets Vulnerable to Remote DoS via OutOfMemoryError when Passed Large Parameter NamesCVE-2026-24819Mediumcom.foxinmy:weixin4j-base: weixin4j has Improperly Controlled Sequential Memory Allocation CVE-2026-24802Mediumcom.github.briandilley.jsonrpc4j:jsonrpc4j: jsonrpc4j has Infinite Loop in RPC Stream Writer CVE-2026-24806Mediumcom.github.liuyueyi.media:batik-codec-fix: Quick-Media Batik Codec FIX package has Code Injection vulnerabilityCVE-2026-24807Mediumcom.github.liuyueyi.media:batik-codec-fix: Quick-Media Batik Codec FIX Package has Buffer Overflow Vulnerability in PNG CodecCVE-2026-24400Highorg.assertj:assertj-core: AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertionCVE-2026-1190Loworg.keycloak:keycloak-services: Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods

Stop the waste.
Protect your environment with Kodem.