Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-58782Mediumorg.apache.jackrabbit:jackrabbit-core: Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted DataCVE-2025-58369Mediumco.fs2:fs2-io_2.12: FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite sideCVE-2025-58056Lowio.netty:netty-codec-http: Netty vulnerable to request smuggling due to incorrect parsing of chunk extensionsGHSA-C7V7-RQFM-F44JMediumcom.vaadin:vaadin: Vaadin Platform possible file bypass via upload validation on the server-sideGHSA-94G8-XV23-7656Mediumcom.vaadin:vaadin-upload-flow: Vaadin Flow Components possible file bypass via upload validation on the server-sideCVE-2025-9467Mediumcom.vaadin:vaadin-server: Vaadin Framework possible file bypass via upload validation on the server-sideCVE-2025-43772Highcom.liferay:com.liferay.portal.workflow.kaleo.forms.web: Liferay Portal Vulnerable to Denial of Service in Kaleo Forms AdminCVE-2025-58057Mediumio.netty:netty-codec-compression: Netty's decoders vulnerable to DoS via zip bomb style attackCVE-2025-55748Criticalorg.xwiki.platform:xwiki-platform-skin-skinx: XWiki configuration files can be accessed through jsx and sx endpointsCVE-2025-55747Criticalorg.xwiki.platform:xwiki-platform-webjars-api: XWiki configuration files can be accessed through the webjars APICVE-2025-58460Mediumio.jenkins.plugins:opentelemetry: Jenkins OpenTelemetry Plugin missing permission check allows capturing credentialsCVE-2025-58458Mediumorg.jenkins-ci.plugins:git-client: Jenkins Git client Plugin file system information disclosure vulnerabilityCVE-2025-58459Mediumorg.jenkins-ci.plugins:global-build-stats: Jenkins global-build-stats Plugin missing permission check can result in graph IDs being enumeratedCVE-2024-43166Loworg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler Incorrect Default Permissions VulnerabilityCVE-2025-9784Highio.undertow:undertow-core: Undertow MadeYouReset HTTP/2 DDoS VulnerabilityCVE-2025-46047Mediumorg.silverpeas.core:silverpeas-core: Silverpeas Core Username Enumeration VulnerabilityCVE-2025-43773Mediumcom.liferay:com.liferay.portal.workflow.kaleo.runtime.impl: Liferay Portal allows improper access through the expandoTableLocalServiceCVE-2025-55202Loworg.opencastproject:opencast-user-interface-configuration: Opencast has a partial path traversal vulnerability in UI configCVE-2025-58059Criticalcom.ritense.valtimo:core: Valtimo scripting engine can be used to gain access to sensitive data or resourcesCVE-2025-58049Mediumorg.xwiki.platform:xwiki-platform-export-pdf-api: XWiki PDF export jobs store sensitive cookies unencrypted in job statusesCVE-2025-26467Highorg.apache.cassandra:cassandra-all: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)CVE-2025-43766Mediumcom.liferay:com.liferay.style.book.web: Liferay Portal allows unrestricted upload of file in the style books componentCVE-2025-43765Mediumcom.liferay:com.liferay.journal.service: Liferay Portal stored cross-site scripting in text field of the web content structureCVE-2025-43764Mediumcom.liferay:com.liferay.portal.workflow.kaleo.designer.web: Liferay Portal ReDoS with Role Name search in KaleoDesignerPortletCVE-2025-43767Mediumcom.liferay:com.liferay.info.impl: Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect

Stop the waste.
Protect your environment with Kodem.