Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-30220Highorg.geoserver.web:gs-web-app: [XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS ServiceCVE-2025-30145Highorg.geoserver.web:gs-web-app: GeoServer Infinite Loop Vulnerability in Jiffle processCVE-2025-27505Mediumorg.geoserver.web:gs-web-app: GeoServer Missing Authorization on REST API IndexCVE-2024-40625Mediumorg.geoserver:gs-rest: Coverage REST API Server Side Request ForgeryCVE-2024-38524Mediumorg.geoserver.web:gs-web-app: GWC Home Page communicate version and revision informationCVE-2024-34711Criticalorg.geoserver.web:gs-web-app: GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)CVE-2024-29198Highorg.geoserver:gs-wfs: GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPostCVE-2025-27817Mediumorg.apache.kafka:kafka-clients: Apache Kafka Client Arbitrary File Read and Server Side Request Forgery VulnerabilityCVE-2025-27818Highorg.apache.kafka:kafka_2.11: Apache Kafka Deserialization of Untrusted Data vulnerabilityCVE-2025-27819Highorg.apache.kafka:kafka_2.10: Apache Kafka Deserialization of Untrusted Data vulnerabilityGHSA-826P-4GCG-35VWCriticalorg.geotools:gt-xsd-core: GeoTools has XML External Entity (XXE) Processing Vulnerability in XSD schema handlingCVE-2025-49128Mediumcom.fasterxml.jackson.core:jackson-core: Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocationCVE-2025-49009Mediumcom.erudika:para-server: Para Inserts Sensitive Information into Log File for Facebook authenticationCVE-2025-27531Highorg.apache.inlong:inlong-manager: Apache InLong Deserialization of Untrusted Data VulnerabilityCVE-2025-5806Highorg.jenkins-ci.plugins:gatling: Jenkins Gatling Plugin Vulnerable to Cross-Site Scripting (XSS)CVE-2025-35036Mediumorg.hibernate.validator:hibernate-validator: Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression LanguageCVE-2025-46548Mediumorg.apache.pekko:pekko-management_2.12: Pekko Management may not properly apply authenticator when Basic Authentication is enabledCVE-2025-45855Mediumxyz.erupt:erupt: Erupt Unrestricted Upload of File with Dangerous Type vulnerabilityCVE-2024-1440Mediumorg.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util: WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpointCVE-2024-8008Mediumorg.wso2.carbon.identity.framework:org.wso2.carbon.identity.user.store.configuration.ui: WSO2 products vulnerable to Cross-site ScriptingCVE-2025-48955Mediumcom.erudika:para-server: Para Server Logs Sensitive InformationCVE-2024-7096Mediumorg.wso2.am:am-parent: WSO2 products vulnerable to privilege escalation due to business logic flaw in SOAP admin servicesCVE-2025-41235Highorg.springframework.cloud:spring-cloud-gateway-server: Spring Cloud Gateway Server Forwards Headers from Untrusted ProxiesCVE-2025-46701Loworg.apache.tomcat:tomcat-catalina: Apache Tomcat - CGI security constraint bypassCVE-2025-48734Highcommons-beanutils:commons-beanutils: Apache Commons Improper Access Control vulnerability

Stop the waste.
Protect your environment with Kodem.