Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-53665Mediumcom.apica:ApicaLoadtest: Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokensCVE-2025-53666Mediumorg.jenkins-ci.plugins:deadmanssnitch: Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text CVE-2025-53656Mediumorg.jenkins-ci.plugins:soapui-pro-functional-testing: Jenkins ReadyAPI Functional Testing Plugin vulnerability stores unencrypted authentication credentialsCVE-2025-53655Mediumorg.jenkins.plugins.statistics.gatherer:statistics-gatherer: Jenkins Statistics Gatherer Plugin does not mask AWS Secret KeyCVE-2025-53654Mediumorg.jenkins.plugins.statistics.gatherer:statistics-gatherer: Jenkins Statistics Gatherer Plugin vulnerability exposes AWS Secret KeyCVE-2025-53651Mediumorg.jenkins-ci.plugins:htmlpublisher: Jenkins HTML Publisher Plugin vulnerability displays controller file system information in its logsCVE-2025-53653Mediumorg.jenkins-ci.plugins:aqua-security-scanner: Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokensCVE-2025-53652Mediumorg.jenkins-ci.tools:git-parameter: Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter checkCVE-2025-53650Mediumorg.jenkins-ci.plugins:credentials-binding: Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messagesCVE-2025-53602Mediumio.zipkin:zipkin-server: Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpointCVE-2025-53103Mediumorg.junit.platform:junit-platform-reporting: junit-platform-reporting can leak Git credentials through its OpenTestReportGeneratingListener CVE-2025-53106Highorg.graylog2:graylog2-server: Graylog vulnerable to privilege escalation through API tokensCVE-2025-26074Criticalorg.conductoross:conductor-core: Conductor vulnerable to OS command injection through unrestricted access to Java classesCVE-2025-53003Highio.jans:jans-config-api-server: Janssen Config API returns results without scope verificationCVE-2025-53393Mediumcom.typesafe.akka:akka-cluster-metrics_3: akka-cluster-metrics uses Java serialization for cluster metricsCVE-2025-32897Loworg.apache.seata:seata-config-core: Apache Seata Vulnerable to Deserialization of Untrusted DataCVE-2025-52999Highcom.fasterxml.jackson.core:jackson-core: jackson-core can throw a StackoverflowError when processing deeply nested dataCVE-2025-5731Mediumorg.infinispan:infinispan-cli-client: Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive InformationCVE-2025-6701Lowcom.xuxueli:xxl-sso: XXL SSO is vulnerable to an Open Redirect through malicious manipulation of the redirect_url argument CVE-2025-6700Lowcom.xuxueli:xxl-sso: Xuxueli XXL-SSO Cross-site Scripting vulnerabilityCVE-2025-52888Highio.qameta.allure.plugins:xunit-xml-plugin: Allure Report allows Improper XXE Restriction via DocumentBuilderFactoryCVE-2025-49574Mediumio.quarkus:quarkus-vertx: Quarkus potentially leaks data when duplicating a duplicated contextGHSA-7CJH-XX4R-QH3FHighio.sentry:sentry-android: sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+CVE-2025-6384Highorg.craftercms:crafter-studio: Crafter Studio Groovy Sandbox BypassCVE-2025-48059Lowcom.powsybl:powsybl-iidm-criteria: PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion

Stop the waste.
Protect your environment with Kodem.