Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-54380Mediumorg.opencastproject:opencast-common: Opencast still publishes global system account credentials CVE-2025-54385Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments APICVE-2025-32429Criticalorg.xwiki.platform:xwiki-platform-distribution-war: XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameterCVE-2025-7962Mediumorg.eclipse.angus:smtp: Jakarta Mail vulnerable to SMTP InjectionCVE-2025-50151Highorg.apache.jena:jena: Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator accessCVE-2025-49656Mediumorg.apache.jena:jena-fuseki: Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki serverCVE-2025-7789Lowcom.xuxueli:xxl-job-admin: xxl-job has Inadequate Encryption Strength CVE-2025-7787Lowcom.xuxueli:xxl-job-core: XXL-JOB is vulnerable to SSRF attacksCVE-2024-9408Highorg.glassfish.main.admingui:console-common: Eclipse GlassFish is vulnerable to Server Side Request Forgery attacks through specific endpointsCVE-2024-9342Mediumorg.glassfish.main.admingui:console-common: Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attemptsCVE-2024-9343Mediumorg.glassfish.main.admingui:console-common: Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration ConsoleCVE-2024-10029Mediumorg.glassfish.main.admingui:console-common: Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration ConsoleCVE-2024-10032Mediumorg.glassfish.main.admingui:console-cluster-plugin: Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration ConsoleCVE-2024-10031Mediumorg.glassfish.main.admingui:console-common: Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modificationsCVE-2025-22227Mediumio.projectreactor.netty:reactor-netty-http: Reactor Netty HTTP is vulnerable to credential leaks during chained redirectsCVE-2025-53622Mediumorg.dspace:dspace-api: DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive FormatCVE-2025-53621Mediumorg.dspace:dspace-api: DSpace is vulnerable to XML External Entity injection during archive imports CVE-2025-48795Mediumorg.apache.cxf:cxf-core: Apache CXF is vulnerable to DoS attacks as entire files are read into memory and loggedCVE-2025-53836Criticalorg.xwiki.rendering:xwiki-rendering-transformation-macro: XWiki Rendering is vulnerable to RCE attacks when processing nested macrosCVE-2025-53835Criticalorg.xwiki.rendering:xwiki-rendering-syntax-xhtml: XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntaxCVE-2025-53689Highorg.apache.jackrabbit:jackrabbit-spi-commons: Apache Jackrabbit vulnerable to blind XXE attack due to insecure document buildCVE-2024-41169Highorg.apache.zeppelin:zeppelin-interpreter: Apache Zeppelin exposes server resources to unauthenticated attackersCVE-2025-30402Highexecutorch: ExecuTorch vulnerable to Heap-based Buffer Overflow attackCVE-2025-48924Mediumorg.apache.commons:commons-lang3: Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputsCVE-2025-53864Mediumcom.nimbusds:nimbus-jose-jwt: Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

Stop the waste.
Protect your environment with Kodem.