Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-59328Mediumorg.apache.fory:fory-core: Apache Fory Deserialization of Untrusted Data vulnerabilityCVE-2025-43791Mediumcom.liferay:com.liferay.dynamic.data.mapping.form.field.type: Liferay Portal vulnerable to Cross-site ScriptingCVE-2025-43793Mediumcom.liferay.portal:com.liferay.portal.impl: Liferay Portal has Improper Validation of Specified Quantity in InputCVE-2025-43792Lowcom.liferay.portal:com.liferay.portal.kernel: Liferay Portal has External Control of System or Configuration SettingsCVE-2025-43794Mediumcom.liferay.portal:com.liferay.portal.impl: Liferay Portal has stored cross-site scripting (XSS) vulnerabilityCVE-2025-43796Highcom.liferay:com.liferay.portal.vulcan.api: Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion AttackCVE-2025-43795Mediumcom.liferay:com.liferay.configuration.admin.web: Liferay Portal's System, Instance and Site Settings are vulnerable to Open RedirectCVE-2025-43787Mediumcom.liferay:com.liferay.users.admin.web: Liferay Portal's selection modal is vulnerable to XSSCVE-2025-43788Mediumcom.liferay:com.liferay.organizations.item.selector.web: Liferay Portal's Organization Selector exposes organization data to remote authenticated usersCVE-2025-43789Lowcom.liferay:com.liferay.comment.web: Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy ExecutionCVE-2025-43790Highcom.liferay:com.liferay.object.service: Liferay Portal is vulnerable to Insecure Direct Object Reference (IDOR) attack through Authentication BypassCVE-2025-43782Mediumcom.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl: Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by NameCVE-2025-43784Mediumcom.liferay:com.liferay.headless.builder.impl: Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive dataCVE-2025-43783Mediumcom.liferay:com.liferay.frontend.editor.ckeditor.web: Liferay Portal is vulnerable to Reflected XSS attack through get_editor pathCVE-2025-43785Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to Stored Cross-site ScriptingCVE-2025-43786Mediumcom.liferay:com.liferay.portal.vulcan.impl: Liferay Portal exposes ERC which can lead to exploit the time response attackCVE-2025-43781Mediumcom.liferay:com.liferay.portal.search.web: Liferay Portal is vulnerable to XSS attack through its search bar portletCVE-2025-43775Mediumcom.liferay:com.liferay.client.extension.web: Liferay Portal is vulnerable to XSS attacks via its remote app title fieldCVE-2024-43115Highorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler vulnerable to Alert Script AttackCVE-2025-43776Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to store Cross-site ScriptingCVE-2025-43777Mediumcom.liferay:com.liferay.portal.security.sso.openid.connect.impl: Liferay Portal exposes 500 status when attempting login with a deleted client secretCVE-2025-43778Mediumcom.liferay:com.liferay.portal.workflow.kaleo.forms.web: Liferay Portal is vulnerable to XSS attack through fieldset name in Kaleo Forms AdminCVE-2025-43774Lowcom.liferay:com.liferay.frontend.taglib.clay: Liferay Portal is vulnerable to XSS attack through its Style Book themeCVE-2025-43763Mediumcom.liferay:com.liferay.object.service: Liferay Portal is vulnerable to SSRF through custom object attachment fieldsCVE-2025-58365Highorg.xwiki.contrib.blog:application-blog-ui: XWiki Blog Application: Privilege Escalation (PR) from account through blog content

Stop the waste.
Protect your environment with Kodem.