Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-43769Mediumcom.liferay:com.liferay.plugins.admin.web: Liferay Portal vulnerable to Stored XSS in Components portletCVE-2025-43768Mediumcom.liferay.portal:com.liferay.portal.impl: Liferay Portal JSONWS API endpoint shares sensitive informationCVE-2025-43770Mediumcom.liferay.portal:com.liferay.portal.kernel: Liferay Portal vulnerable to Reflected XSS with the referer and forward parameterCVE-2025-43761Mediumcom.liferay:com.liferay.frontend.editor.ckeditor.web: Liferay Portal Reflected XSS in CKeditor 4.21.0 endpointCVE-2025-43759Mediumcom.liferay:com.liferay.layout.impl: Liferay Portal users are able to add system admin portlets to pagesCVE-2025-43758Mediumcom.liferay:com.liferay.frontend.js.web: Liferay Portal's unauthenticated users can access loaded files via URL before submitting the object entryCVE-2025-43762Mediumcom.liferay:com.liferay.dynamic.data.mapping.form.web: Liferay Portal users can upload an unlimited amount of filesCVE-2025-43760Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirectCVE-2025-43751Mediumcom.liferay:com.liferay.login.web: Liferay Portal User Enumeration Vulnerability via the Create Account PageCVE-2025-51825Mediumorg.jeecgframework.boot:jeecg-boot-base-core: JeecgBoot SQL Injection VulnerabilityCVE-2025-9340Loworg.bouncycastle:bc-fips: Bouncy Castle for Java has Out-of-Bounds Write VulnerabilityCVE-2025-9341Mediumorg.bouncycastle:bc-fips: Bouncy Castle for Java has Uncontrolled Resource Consumption VulnerabilityCVE-2025-43752Mediumcom.liferay.portal:release.portal.bom: Liferay Portal's Unlimited File Upload Could Result in DoSCVE-2025-43753Lowcom.liferay:com.liferay.layout.taglib: Liferay Portal Reflected Cross-Site Scripting Vulnerability via Form ContainerCVE-2025-51606Highcn.hippo4j:hippo4j-core: hippo4j Includes Hard Coded Secret Key in JWT CreationCVE-2025-43754Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Username Enumeration VulnerabilityCVE-2025-43755Mediumcom.liferay:com.liferay.layout.admin.web: Liferay Portal Stored Cross-Site Scripting Vulnerability via GroupPagesPortlet_type ParameterCVE-2025-43756Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Reflected Cross-Site Scripting Vulnerability via snippet ParameterCVE-2025-9264Lowcom.xuxueli:xxl-job-admin: xxl-job Jobs Handler remove function allows improper control of resource identifiers via ID parameterCVE-2025-9263Lowcom.xuxueli:xxl-job-admin: xxl-job Vulnerable to Resource Injection and Authorization Bypass Through User-Controlled KeyCVE-2025-54988Criticalorg.apache.tika:tika-parser-pdf-module: Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDFCVE-2025-43746Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to Cross-Site Scripting in Dynamic Data MappingCVE-2025-43757Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition ParameterCVE-2025-5115Highorg.eclipse.jetty.http2:http2-common: Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerabilityCVE-2025-43748Highcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to Cross-Site Request Forgery

Stop the waste.
Protect your environment with Kodem.