Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-48058Mediumcom.powsybl:powsybl-commons: PowSyBl Core contains Polynomial REDoS’esCVE-2025-47771Highcom.powsybl:powsybl-math: PowSyBl Core allows deserialization of untrusted SparseMatrix dataCVE-2025-47293Lowcom.powsybl:powsybl-commons: PowSyBl Core XML Reader allows XXE and SSRFCVE-2025-32896Loworg.apache.seatunnel:seatunnel-engine-server: Apache SeaTunnel: Unauthenticated insecure accessCVE-2025-3594Highcom.liferay:com.liferay.server.admin.web: Liferay Portal path traversal vulnerability with the downloading and installation of XugglerCVE-2025-49124Mediumorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat installer for Windows has an untrusted search path vulnerabilityCVE-2025-49125Mediumorg.apache.tomcat:tomcat-catalina: Apache Tomcat - Security constraint bypass for pre/post-resourcesCVE-2025-48988Highorg.apache.tomcat:tomcat-catalina: Apache Tomcat - DoS in multipart uploadCVE-2025-48976Highorg.apache.commons:commons-fileupload2-core: Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headersCVE-2025-3526Highcom.liferay.portal:com.liferay.portal.kernel: Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP sessionCVE-2025-3602Highcom.liferay:com.liferay.portal.vulcan.impl: Liferay Portal does not limit the depth of a GraphQL queriesCVE-2025-49585Highorg.xwiki.platform:xwiki-platform-security-requiredrights-default: XWiki does not require right warnings for XClass definitionsCVE-2025-49586Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki allows remote code execution through preview of XClass changes in AWM editorCVE-2025-49587Mediumorg.xwiki.platform:xwiki-platform-notifications-notifiers-default: XWiki does not require right warnings for notification displayer objectsCVE-2025-49584Highorg.xwiki.platform:xwiki-platform-rest-server: XWiki makes title of inaccessible pages available through the class property values REST APICVE-2025-49583Mediumorg.xwiki.platform:xwiki-platform-notifications-notifiers-default: XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin rightCVE-2025-49581Highorg.xwiki.platform:xwiki-platform-rendering-wikimacro-store: XWiki allows remote code execution through default value of wiki macro wiki-type parametersCVE-2025-49582Highorg.xwiki.platform:xwiki-platform-rendering-xwiki: XWiki's required right warnings for macros are incompleteCVE-2025-49580Highorg.xwiki.platform:xwiki-platform-refactoring-default: XWiki allows privilege escalation through link refactoringCVE-2025-46096Mediumorg.noear:solon-faas-luffy: Solon Vulnerable to Directory TraversalCVE-2025-41234Mediumorg.springframework:spring-web: Spring Framework vulnerable to a reflected file download (RFD)CVE-2024-56158Criticalorg.xwiki.platform:xwiki-platform-oldcore: XWiki allows SQL injection in query endpoint of REST API with OracleCVE-2025-49146Highorg.postgresql:postgresql: pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require ConfigurationGHSA-68CF-J696-WVV9Highorg.geoserver:gs-wfs: GeoServer vulnerable to SSRF in TestWfsPost for specific targets, e.g. PHP + NginxGHSA-2P76-GC46-5FVCHighorg.geonetwork-opensource:gn-web-app: GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint

Stop the waste.
Protect your environment with Kodem.