Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-64144Mediumio.jenkins.plugins:byteguard-build-actions: Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml filesCVE-2025-62784Mediumde.themoep:inventorygui: InventoryGui allows item duplication in GUIs which use GuiStorageElementCVE-2025-12390Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to session takeovers due to reuse of session identifiersCVE-2025-62258Highcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to CSRF in Headless APIsCVE-2025-62260Highcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to DoS via Crafted Headless API RequestCVE-2025-62259Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Does Not Limit Access to APIs Before Email VerificationCVE-2025-62261Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Stores Password Reset Tokens in Plain TextCVE-2025-62262Mediumcom.liferay:com.liferay.portal.security.ldap.impl: Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import FeatureCVE-2025-62263Mediumcom.liferay:com.liferay.account.admin.web: Liferay Portal Vulnerable to Cross-Site ScriptingCVE-2025-62253Mediumcom.liferay:com.liferay.layout.admin.web: Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameterCVE-2025-11419Highorg.keycloak:keycloak-quarkus-dist: Keycloak TLS Client-Initiated Renegotiation Denial of ServiceCVE-2025-62782Mediumde.themoep:inventorygui: InventoryGui allows item duplication with experimental "Bundle" item in GUIs which use GuiStorageElementCVE-2025-62783Mediumde.themoep:inventorygui: InventoryGui affected by item duplication in GUIs which use GuiStorageElementCVE-2025-55754Loworg.apache.tomcat:tomcat: Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control SequencesCVE-2025-61795Loworg.apache.tomcat:tomcat: Apache Tomcat Vulnerable to Improper Resource Shutdown or ReleaseCVE-2025-55752Highorg.apache.tomcat:tomcat: Apache Tomcat Vulnerable to Relative Path TraversalCVE-2025-12194Mediumorg.bouncycastle:bc-fips: Bouncy Castle Vulnerable to Uncontrolled Resource ConsumptionCVE-2025-62254Mediumcom.liferay.portal:com.liferay.portal.impl: Liferay Portal ComboServlet denial of service via large file combinationCVE-2025-62255Lowcom.liferay:com.liferay.knowledge.base.web: Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article pageCVE-2025-60837Mediumnet.mingsoft:ms-mcms: MCMS reflected cross-site scripting (XSS) vulnerabilityCVE-2025-12110Mediumorg.keycloak:keycloak-services: Keycloak does not invalidate offline sessions when the offline_access scope is removedCVE-2025-62256Mediumcom.liferay:com.liferay.portal.security.auth.verifier: Liferay Portal and DXP do not properly restrict access to OpenAPICVE-2025-11429Mediumorg.keycloak:keycloak-services: Keycloak does not invalidate sessions when "Remember Me" is disabledCVE-2025-62247Lowcom.liferay:com.liferay.search.experiences.service: Liferay Portal and DXP are Missing Authorization in Collection ProviderCVE-2025-62248Mediumcom.liferay:com.liferay.dynamic.data.mapping.web: Liferay Portal and Liferay DXP vulnerable to reflected cross-site scripting (XSS)

Stop the waste.
Protect your environment with Kodem.