Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-68384Mediumorg.elasticsearch.plugin:x-pack-security: Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings DataCVE-2025-68161Mediumorg.apache.logging.log4j:log4j-core: Apache Log4j does not verify the TLS hostname in its Socket AppenderCVE-2025-14763Mediumsoftware.amazon.encryption.s3:amazon-s3-encryption-client-java: Amazon S3 Encryption Client for Java has a Key Commitment IssueCVE-2024-29371Highorg.bitbucket.b_c:jose4j: jose4j is vulnerable to DoS via compressed JWE contentCVE-2025-68113Mediumaltcha-lib: ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and ReplayCVE-2025-67735Mediumio.netty:netty-codec-http: Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoderCVE-2025-37731Mediumorg.elasticsearch:elasticsearch: Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client CertificatesCVE-2025-14674Mediumcom.aizuda:snail-job: snail-job is vulnerable to Code Injection through QLExpressEngine.doEval functionCVE-2025-67721Highio.airlift:aircompressor-v3: aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output bufferCVE-2025-3586Highcom.liferay:com.liferay.object.service: Liferay Portal and DXP Instance Admin can execute code using Objects Actions and ValidationsCVE-2025-53960Highorg.apache.streampark:streampark: Apache StreamPark: Use the user’s password as the secret key VulnerabilityCVE-2025-54981Highorg.apache.streampark:streampark: Apache StreamPark uses a Weak Encryption AlgorithmCVE-2025-54947Highorg.apache.streampark:streampark: Apache StreamPark has a hard-coded encryption keyCVE-2025-26866Highorg.apache.hugegraph:hg-pd-core: Apache HugeGraph-Server: RAFT and deserialization vulnerabilityCVE-2025-14518Mediumtech.powerjob:powerjob-common: PowerJob has a server-side request forgery vulnerability in PingPongUtils.javaCVE-2025-67505Highcom.okta.sdk:okta-sdk-root: Race condition in the Okta Java SDKCVE-2025-66033Mediumcom.okta.sdk:okta-sdk-root: Improper Memory Cleanup in the Okta Java SDKCVE-2025-67641Highio.jenkins.plugins:coverage: Jenkins Coverage Plugin has a stored cross-site scripting (XSS) vulnerabilityCVE-2025-67642Mediumcom.datapipe.jenkins.plugins:hashicorp-vault-plugin: Jenkins HashiCorp Vault Plugin exposes system-scoped Vault credentialsCVE-2025-67643Mediumorg.jenkinsci.plugins:pipeline-reporter-by-redpen: Jenkins Redpen - Pipeline Reporter for Jira Plugin has a path traversal vulnerabilityCVE-2025-67638Mediumorg.jenkins-ci.main:jenkins-core: Jenkins's build authorization token is stored and displayed in plain textCVE-2025-67635Highorg.jenkins-ci.main:jenkins-core: Jenkins has a Denial of service vulnerability in HTTP-based CLICVE-2025-67637Mediumorg.jenkins-ci.main:jenkins-core: Jenkins's build authorization token is stored and displayed in plain textCVE-2025-67636Mediumorg.jenkins-ci.main:jenkins-core: Jenkins is missing a permission check on password fieldsCVE-2025-67639Loworg.jenkins-ci.main:jenkins-core: Jenkins has a CSRF vulnerability on the login form

Stop the waste.
Protect your environment with Kodem.