Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-67640Mediumorg.jenkins-ci.plugins:git-client: Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client PluginCVE-2025-66474Highorg.xwiki.rendering:xwiki-rendering-xml: XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injectionCVE-2025-66473Highorg.xwiki.platform:xwiki-platform-rest-server: XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikisCVE-2025-66472Mediumorg.xwiki.platform:xwiki-platform-flamingo-skin-resources: XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplicationCVE-2025-66675Highorg.apache.struts:struts2-core: Apache Struts has a Denial of Service vulnerabilityCVE-2025-14082Loworg.keycloak:keycloak-services: Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissionsCVE-2025-14306Criticalnet.sf.robocode:robocode.core: Robocode vulnerable to Directory Traversal in recursivelyDelete MethodCVE-2025-14307Criticalnet.sf.robocode:robocode.battle: Robocode has an insecure temporary file creation vulnerability in the AutoExtract componentGHSA-93FV-4PM9-XP28Mediumnet.dv8tion:JDA: JDA (Java Discord API) downloads external URLs when updating message componentsCVE-2025-66623Highio.strimzi:strimzi: Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operandsCVE-2025-66566Highat.yawk.lz4:lz4-java: yawkat LZ4 Java has a possible information leak in Java safe decompressorCVE-2025-66516Criticalorg.apache.tika:tika-core: Apache Tika has XXE vulnerabilityCVE-2025-11222Mediumcom.linecorp.centraldogma:centraldogma-server-auth-shiro: Central Dogma's Login Function Has an Open Redirect VulnerabilityCVE-2024-3884Highio.undertow:undertow-core: Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencodedCVE-2025-66453Loworg.mozilla:rhino: Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` functionCVE-2025-13472Mediumcom.blazemeter.plugins:BlazeMeterJenkinsPlugin: BlazeMeter Jenkins Plugin is Missing Authorization for Available ResourcesCVE-2025-10939Loworg.keycloak:keycloak-quarkus-server: Keycloak unable to restrict access to the admin consoleCVE-2025-11538Mediumorg.keycloak:keycloak-quarkus-dist: Keycloak has debug default bind addressCVE-2025-14874Highnodemailer: Nodemailer’s addressparser is vulnerable to DoS caused by recursive callsCVE-2025-55749Highorg.xwiki.platform:xwiki-platform-tool-jetty-resources: XWiki Jetty Package (XJetty) allows accessing any application file through URLCVE-2025-64775Highorg.apache.struts:struts2-core: Apache Struts is Vulnerable to DoS via File LeakCVE-2025-13805Loworg.nutz:nutzboot-parent: NutzBoot vulnerable to deserializationCVE-2025-13806Mediumorg.nutz:nutzboot-parent: NutzBoot Incorrect Privilege Assignment vulnerabilityCVE-2025-13804Loworg.nutz:nutzboot-parent: NutzBoot vulnerable to information disclosureCVE-2025-12183Highat.yawk.lz4:lz4-java: LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS

Stop the waste.
Protect your environment with Kodem.