Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-62244Mediumcom.liferay:com.liferay.change.tracking.web: Liferay Publications vulnerable to Authorization Bypass Through User-Controlled KeyCVE-2025-62243Mediumcom.liferay:com.liferay.change.tracking.web: Liferay Publications is vulnerable to Incorrect AuthorizationCVE-2025-62245Mediumcom.liferay:com.liferay.change.tracking.web: Liferay Portal is vulnerable to CSRF through publication commentsCVE-2025-11581Mediumtech.powerjob:powerjob-server-starter: PowerJob OpenAPIController is missing authorization CVE-2025-11580Mediumtech.powerjob:powerjob: PowerJob has Missing Authorization in its /user/list fileCVE-2025-62237Mediumcom.liferay.commerce:com.liferay.commerce.order.web: Liferay Portal Commerce is vulnerable to XSS through account "name" fieldCVE-2025-62238Mediumcom.liferay:com.liferay.account.admin.web: Liferay Portal's Membership page is vulnerable to XSS through “name“ text fieldCVE-2025-62239Mediumcom.liferay:com.liferay.portal.workflow.kaleo.designer.web: Liferay Portal is vulnerable to XSS through its workflow process builderCVE-2025-37727Mediumorg.elasticsearch:elasticsearch: Elasticsearch: Insertion of Sensitive Information into Log File via reindex APICVE-2025-30001Highorg.apache.streampark:streampark: Apache StreamPark contains an Incorrect Execution-Assigned Permissions vulnerabilityCVE-2025-62240Mediumcom.liferay:com.liferay.calendar.web: Liferay Portal is vulnerable to XSS through its Calendar Events parametersCVE-2025-62228Mediumorg.apache.flink:flink-cdc-pipeline-connectors: Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiersCVE-2025-9162Mediumorg.keycloak:keycloak-model-storage-services: Keycloak Potential Variable Reference in Model Storage ServicesCVE-2025-61788Mediumorg.opencastproject:opencast-common: Opencast's Paella Player 7 is vulnerable to Cross-Site ScriptingCVE-2025-43771Mediumcom.liferay:com.liferay.flags.web: Liferay Portal Notifications Widget has multiple XSS vulnerabilities through various text fieldsCVE-2025-43830Mediumcom.liferay.portal:release.portal.bom: Liferay Portal is vulnerable to Stored XSS through Forms text type fieldCVE-2025-43829Mediumcom.liferay.commerce:com.liferay.commerce.shop.by.diagram.web: Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG fileCVE-2025-43821Mediumcom.liferay.commerce:com.liferay.commerce.product.service: Liferay Portal is vulnerable to XSS through its Commerce Product's Name text fieldCVE-2025-43823Mediumcom.liferay.portal:release.portal.bom: Liferay Portal is vulnerable to XSS through its Commerce Search Result widgetCVE-2025-43822Mediumcom.liferay.portal:release.portal.bom: Liferay Portal has multiple Stored XSS vulnerabilities on its View Order pageCVE-2025-43824Mediumcom.liferay.portal:release.portal.bom: Liferay Profile Widget does not prevent vCard extension spoofingCVE-2025-52472Criticalorg.xwiki.platform:xwiki-platform-rest-server: XWiki Platform is vulnerable to HQL injection via wiki and space search REST APICVE-2025-49594Criticalorg.xwiki.contrib.oidc:oidc-authenticator: XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can viewCVE-2025-43825Mediumcom.liferay:com.liferay.portal.template.freemarker: Liferay Portal exposes sensitive user data through its Freemarker templateCVE-2025-61733Highorg.apache.kylin:kylin: Apache Kylin Authentication Bypass Vulnerability

Stop the waste.
Protect your environment with Kodem.