Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-66372Loworg.mustangproject:library: Mustangproject allows exfiltrating files via XXE attacksCVE-2025-3261Mediumorg.thingsboard:application: ThingsBoard allows an authenticated user to upload malicious SVG imagesCVE-2025-54057Mediumorg.apache.skywalking:apm-webapp: Apache SkyWalking has a stored XSS vulnerabilityCVE-2025-62728Highorg.apache.hive:hive-common: Hive Metastore Server is vulnerable to SQL InjectionCVE-2025-59390Criticalorg.apache.druid:druid: Apache Druid’s Kerberos authenticator uses a weak fallback secretCVE-2025-66021Highcom.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer: OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization CVE-2025-9624Highorg.opensearch:opensearch-common: OpenSearch is vulnerable to DoS via complex query_string inputsCVE-2025-58360Highorg.geoserver.web:gs-web-app: GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap featureCVE-2025-21621Mediumorg.geoserver.web:gs-web-app: GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML formatCVE-2025-65998Highorg.apache.syncope:syncope-core: Apache Syncope's AES encryption stores hard-coded passwords in internal databaseCVE-2025-13435Lowcn.dreampie:resty: Resty has a Path Traversal vulnerabilityCVE-2025-64408Criticalorg.apache.causeway.commons:causeway-commons: Apache Causeway vulnerable to deserialization in JavaCVE-2025-65089Mediumcom.xwiki.pro:xwiki-pro-macros-ui: XWiki view file macro: User can view content of office file without view rights on the attachment CVE-2025-12383Criticalorg.glassfish.jersey.core:jersey-client: Eclipse Jersey has a Race ConditionCVE-2025-54990Mediumcom.xwiki.admintools:application-admintools: XWiki AdminTools application doesn't set permissions on the AdminTools spaceCVE-2025-13266Mediumio.github.wwwlike:vlife-base: vlife-base has Path Traversal vulnerabilityCVE-2025-13262Mediumlsfusion.platform:web-client: lsFusion Platform has a Path Traversal vulnerabilityCVE-2025-13265Mediumlsfusion.platform:server: lsFusion Server is vulnerable to Path Traversal through its unpackFile functionCVE-2025-13261Mediumlsfusion.platform:web-client: lsFusion Platform has a Path Traversal vulnerabilityGHSA-7XW4-G7MM-R4HHHighsoftware.amazon.jdbc:aws-advanced-jdbc-wrapper: Amazon Web Services Advanced JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instanceCVE-2025-64099Highorg.openidentityplatform.openam:openam-oauth2: OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed CVE-2025-64518Highorg.cyclonedx:cyclonedx-core-java: CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection CVE-2025-10713Mediumorg.wso2.carbon.mediation:org.wso2.carbon.localentry: WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacksGHSA-J2PC-V64R-MV4FLowio.github.ascopes:protobuf-maven-plugin: Protobuf Maven Plugin protocDigest is ignored when using protoc from PATHCVE-2025-62275Mediumcom.liferay:com.liferay.blogs.item.selector.web: Liferay Portal and DXP do not check permissions of images in a blog entry

Stop the waste.
Protect your environment with Kodem.