Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-43749Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Unauthenticated File Access via URLCVE-2025-43750Mediumcom.liferay:com.liferay.dynamic.data.mapping.form.web: Liferay Portal Unvalidated File UploadCVE-2025-43741Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to Cross-Site Scripting via assetTagNames ParameterCVE-2025-43742Mediumcom.liferay:com.liferay.layout.type.controller.display.page: Liferay Portal Vulnerable to Cross-Site Scripting through URLsCVE-2024-39954Mediumorg.apache.eventmesh:eventmesh-runtime: Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.javaCVE-2025-43744Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to Cross-Site Scripting via DDM Structure Field LabelsCVE-2025-43743Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Enumeration Discrepancy in CalendarsCVE-2025-43745Mediumcom.liferay.portal:release.portal.bom: Liferay Portal CSRF Vulnerability via Endpoint ParameterCVE-2025-43737Mediumcom.liferay:com.liferay.journal.web: Liferay Portal Vulnerable to Cross-Site Scripting via backURL ParamterCVE-2025-43738Mediumcom.liferay:com.liferay.expando.web: Liferay Portal Reflected Cross-Site Scripting Vulnerability in displayType ParameterCVE-2025-43740Mediumcom.liferay.portal:release.portal.bom: Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards FeatureCVE-2025-43739Mediumcom.liferay:com.liferay.calendar.service: Liferay Portal Email Modification Vulnerability via Calendar PortletCVE-2025-43731Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to Cross-Site ScriptingCVE-2025-3639Lowcom.liferay.portal:release.portal.bom: Liferay Portal Login Bypass VulnerabilityCVE-2025-43732Mediumcom.liferay:com.liferay.roles.selector.web: Liferay Portal Vulnerable to Insecure Direct Object ReferenceCVE-2025-43733Lowcom.liferay:com.liferay.layout.taglib: Liferay Portal Vulnerable to Cross-Site Scripting CVE-2025-41242Mediumorg.springframework:spring-webmvc: Spring Framework MVC Applications Path Traversal VulnerabilityCVE-2025-9092Loworg.bouncycastle:bc-fips: Bouncy Castle for Java Uncontrolled Resource Consumption VulnerabilityCVE-2025-55163Highio.netty:netty-codec-http2: Netty affected by MadeYouReset HTTP/2 DDoS vulnerabilityCVE-2025-48989Highorg.apache.tomcat:tomcat-coyote: Apache Tomcat Improper Resource Shutdown or Release vulnerabilityCVE-2025-55668Mediumorg.apache.tomcat:tomcat-catalina: Apache Tomcat Session Fixation vulnerabilityCVE-2025-8916Mediumorg.bouncycastle:bcpkix-fips: Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive AllocationCVE-2025-43734Mediumcom.liferay.portal:release.portal.bom: Liferay Portal 7.4.0 and Liferay DXP have a reflected cross-site scripting (XSS) vulnerabilityCVE-2025-43735Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP have a reflected cross-site scripting vulnerabilityCVE-2025-8885Mediumorg.bouncycastle:bcprov-jdk14: Bouncy Castle for Java on All (API modules) allows Excessive Allocation

Stop the waste.
Protect your environment with Kodem.