Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-43736Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP have a Denial Of Service via File Upload (DOS) vulnerabilityCVE-2025-4581Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to Server-Side Request ForgeryCVE-2025-4655Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to Server-Side Request ForgeryCVE-2025-4576Mediumcom.liferay:com.liferay.blogs.web: Liferay Portal Reflected XSS in blogs-webCVE-2025-48913Mediumorg.apache.cxf:cxf-rt-transports-jms: Apache CXF: Untrusted JMS configuration can lead to RCECVE-2025-53606Highorg.apache.seata:seata-serializer-fury: Apache Seata: Deserialization of untrusted Data in Apache Seata ServerCVE-2025-30404Criticalexecutorch: ExecuTorch integer overflow vulnerabilityCVE-2025-54949Criticalexecutorch: ExecuTorch heap buffer overflow vulnerabilityCVE-2025-54950Criticalexecutorch: ExecuTorch out-of-bounds access vulnerabilityCVE-2025-30405Criticalexecutorch: ExecuTorch integer overflow vulnerabilityCVE-2025-54951Criticalexecutorch: ExecuTorch vulnerable to Heap-based Buffer OverflowCVE-2025-54125Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki exposes passwords and emails stored in fields not named password/email in xml.vmCVE-2025-54124Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki leaks password hashes and other accessible password propertiesCVE-2025-32430Mediumorg.xwiki.platform:xwiki-platform-web-templates: XWiki allows Reflected XSS in two templatesCVE-2025-4604Mediumcom.liferay:com.liferay.captcha.impl: Liferay Portal CAPTCHA Bypass for Gogo ShellCVE-2024-41177Mediumorg.apache.zeppelin:zeppelin-web: Apache Zeppelin: XSS in the Helium moduleCVE-2024-52279Mediumorg.apache.zeppelin:zeppelin-jdbc: Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection stringCVE-2024-51775Mediumorg.apache.zeppelin:zeppelin-shell: Apache Zeppelin: Missing Origin Validation in WebSockets vulnerabilityGHSA-2RJV-CV85-XHGMMediumorg.opensearch.plugin:opensearch-security: OpenSearch unauthorized data access on fields protected by field level security if field is a member of an objectGHSA-RRMM-WQ7Q-H4V5Mediumorg.opensearch.plugin:opensearch-security: OpenSearch unauthorized data access on fields protected by field masking for fields of type ip, geo_point, geo_shape, xy_point, xy_shapeCVE-2025-24853Mediumorg.apache.jspwiki:jspwiki-main: Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability via Header Link RenderingCVE-2025-24854Mediumorg.apache.jspwiki:jspwiki-main: Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability in the Image PluginCVE-2025-54656Mediumorg.apache.struts:struts-extras: Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs VulnerabilityCVE-2025-7784Mediumorg.keycloak:keycloak-services: Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)CVE-2025-7365Mediumorg.keycloak:keycloak-services: Keycloak phishing attack via email verification step in first login flow

Stop the waste.
Protect your environment with Kodem.