Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-61735Highorg.apache.kylin:kylin: Apache Kylin Server-Side Request Forgery (SSRF) VulnerabilityCVE-2025-61734Highorg.apache.kylin:kylin: Apache Kylin Files or Directories Accessible to External PartiesCVE-2025-11226Mediumch.qos.logback:logback-core: QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingCVE-2025-43826Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to XSS in Web Content translationCVE-2025-43827Mediumcom.liferay:com.liferay.portal.security.audit.web: Liferay Portal Vulnerable to IDOR via audit eventsCVE-2025-43812Mediumcom.liferay.portal:release.portal.bom: Liferay Portal vulnerable to cross-site scripting in the web content templateCVE-2025-43820Mediumcom.liferay.portal:release.portal.bom: Liferay Portal vulnerable to cross-site scripting in the Calendar widgetCVE-2025-43818Mediumcom.liferay:com.liferay.calendar.web: Liferay Portal vulnerable to cross-site scripting in the Calendar widgetCVE-2025-43815Mediumcom.liferay:com.liferay.product.navigation.control.menu.web: Liferay Portal vulnerable to reflected cross-site scripting on the page configuration pageCVE-2025-43811Mediumcom.liferay:com.liferay.item.selector.web: Liferay Portal vulnerable to cross-site scripting in the related asset selectorCVE-2025-43817Mediumcom.liferay.portal:release.portal.bom: Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameterCVE-2025-43813Mediumcom.liferay.portal:release.portal.bom: Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServletCVE-2025-59952Highio.minio:minio: MinIO Java Client XML Tag Value Substitution VulnerabilityCVE-2025-1396Loworg.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt: WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabledCVE-2025-56769Highcn.hutool:hutool-extra: Hutool allows remote code execution (RCE) via the QLExpressEngine classCVE-2025-43816Mediumcom.liferay:com.liferay.portal.vulcan.impl: Liferay Portal and DXP vulnerable to a memory leakCVE-2025-58457Mediumorg.apache.zookeeper:zookeeper: Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore CommandsCVE-2025-48459Criticalorg.apache.iotdb:iotdb-confignode: Apache IoTDB: Deserialization of untrusted DataCVE-2025-48392Mediumorg.apache.iotdb:iotdb-core: Apache IoTDB: DoS VulnerabilityCVE-2025-43819Mediumcom.liferay:com.liferay.saml.impl: Liferay Portal and DXP does not properly expire sessionsCVE-2024-6429Mediumorg.wso2.identity.apps:authentication-portal: WSO2 Identity Server Apps allows content spoofing in logsCVE-2025-59822Mediumorg.http4s:http4s-ember-core_2.12: Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sectionCVE-2025-4760Mediumorg.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api: WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerabilityCVE-2025-43810Mediumcom.liferay.commerce:com.liferay.commerce.service: Liferay Portal and DXP allows users to add a note to a different virtual instanceCVE-2025-43814Mediumcom.liferay:com.liferay.portal.security.audit.event.generators.user.management: Liferay Portal and DXP audit events record password reminder answers

Stop the waste.
Protect your environment with Kodem.