Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-14969Mediumorg.hibernate.reactive:hibernate-reactive-core: Hibernate Reactive Vulnerable to DoS via Connection Pool ExhaustionCVE-2026-24656Loworg.apache.karaf.decanter.collector:org.apache.karaf.decanter.collector.log.socket: Apache Karaf Decanter has Deserialization of Untrusted Data in its Log Socket CollectorCVE-2016-15057Criticalorg.apache.continuum:continuum: Apache Continuum vulnerable to Command Injection through Installations REST APICVE-2025-27821Highorg.apache.hadoop:hadoop-hdfs-native-client: Apache Hadoop HDFS Native Client has Out-of-bounds Write Vulnerability CVE-2026-24128Mediumorg.xwiki.platform:xwiki-platform-web-templates: XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error MessagesCVE-2026-0603Highorg.hibernate:hibernate-core: Hibernate vulnerable to SQL InjectionCVE-2025-22234Mediumorg.springframework.security:spring-security-core: Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvideCVE-2026-1225Lowch.qos.logback:logback-core: Logback allows an attacker to instantiate classes already present on the class pathCVE-2026-22022Highorg.apache.solr:solr-core: Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPluginCVE-2026-22444Highorg.apache.solr:solr-core: Apache Solr: Insufficient file-access checking in standalone core-creation requestsCVE-2025-14083Loworg.keycloak:keycloak-services: Keycloak Admin REST API exposes backend schema and rulesCVE-2025-14559Mediumorg.keycloak:keycloak-services: Keycloak services allows the issuance of access and refresh tokens for disabled usersCVE-2026-1035Loworg.keycloak:keycloak-services: Keycloak does not validate and update refresh token usage atomicallyCVE-2025-65482Criticalfr.opensagres.xdocreport:fr.opensagres.xdocreport.document: XDocReport affected by an XML External Entity (XXE) vulnerabilityCVE-2025-64087Criticalfr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarker: XDocReport affected by a Server-Side Template Injection (SSTI) vulnerabilityCVE-2026-1180Mediumorg.keycloak:keycloak-adapter-core: Keycloak’s OpenID Connect Dynamic Client Registration feature affected by Server-Side Request Forgery (SSRF)CVE-2025-59355Mediumorg.apache.linkis:linkis-metadata: Apache Linkis: Password ExposureCVE-2025-29847Highorg.apache.linkis:linkis: Apache Linkis: Arbitrary File Read via Double URL Encoding BypassCVE-2026-1050Mediumnet.risesoft:risenet-y9boot-support-platform-service: risesoft-y9 Digital-Infrastructure has a SQL injection vulnerabilityCVE-2025-15104Mediumnu.validator:validator: Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerabilityCVE-2026-0858Lownet.sourceforge.plantuml:plantuml: PlantUML is vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagramsCVE-2026-1002Mediumio.vertx:vertx-core: Vert.x Web static handler component cache can be manipulated to deny the access to static filesCVE-2026-0976Loworg.keycloak:keycloak-quarkus-server: Keycloak has an improper input validation vulnerabilityCVE-2025-66169Mediumorg.apache.camel:camel-neo4j: Apache Camel camel-neo4j component is vulnerable to cypher injectionCVE-2025-68931Highnet.gleske:jervis: Jervis's AES CBC Mode is Without Authentication

Stop the waste.
Protect your environment with Kodem.