Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-32968Highorg.xwiki.platform:xwiki-platform-oldcore: org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query APICVE-2025-32961Mediumcom.haulmont.addon.jpawebapi:jpawebapi-jpawebapi: XSS in the /download Endpoint of the JPA Web APICVE-2025-32960Mediumcom.haulmont.addon.restapi:restapi-rest-api: XSS in the /files Endpoint of the Generic REST APICVE-2025-32959Mediumcom.haulmont.cuba:cuba-core: Cuba has a DoS in the File StorageCVE-2025-32952Mediumio.jmix.localfs:jmix-localfs: io.jmix.localfs:jmix-localfs affected by DoS in the Local File StorageCVE-2025-32951Mediumio.jmix.rest:jmix-rest: io.jmix.rest:jmix-rest allows XSS in the /files Endpoint of the Generic REST APICVE-2025-32950Mediumio.jmix.localfs:jmix-localfs: io.jmix.localfs:jmix-localfs has a Path Traversal in Local File StorageCVE-2025-29287Criticalnet.mingsoft:ms-mcms: MCMS allows arbitrary file uploads in the ueditor componentCVE-2024-42699Loworg.opencms:opencms-core: OpenCMS Cross-Site Scripting vulnerabilityCVE-2024-41446Mediumorg.opencms:opencms-core: OpenCMS cross-site scripting (XSS) vulnerabilityCVE-2024-41447Mediumorg.opencms:opencms-core: Alkacon OpenCMS stored cross-site scripting (XSS) vulnerabilityCVE-2024-55238Highorg.open-metadata:openmetadata-service: OpenMetadata SQL InjectionCVE-2025-3760Mediumcom.liferay.portal:release.portal.bom: Liferay Cross-site Scripting vulnerabilityCVE-2025-32783Mediumorg.xwiki.platform:xwiki-platform-messagestream: Unregistered users can see "public" messages from a closed wiki via notifications from a different wikiCVE-2025-3588Mediumorg.jsonschema2pojo:jsonschema2pojo-core: jsonschema2pojo has Improper Restriction of Operations within the Bounds of a Memory BufferCVE-2025-27391Mediumorg.apache.activemq:artemis-project: Apache ActiveMQ Artemis Vulnerable to Insertion of Sensitive Information into Log FileCVE-2025-31672Mediumorg.apache.poi:poi-ooxml: Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File ParsingCVE-2025-30677Mediumorg.apache.pulsar:pulsar-io-kafka-connect-adaptor: Apache Pulsar Kafka Connector Logs Sensitive Information in Application LogsCVE-2024-52981Mediumorg.elasticsearch:elasticsearch: Elasticsearch Vulnerable to Stack Overflow due to a Large RecursionCVE-2024-52980Mediumorg.elasticsearch:elasticsearch: Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` FunctionCVE-2025-30373Mediumorg.graylog2:graylog2-server: Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong valueCVE-2025-31487Highorg.xwiki.contrib.jira:jira-macro-default: The XWiki JIRA extension allows data leak through an XXE attack by using a fake JIRA serverCVE-2025-29085Highcom.vip.saturn:saturn-console: Vipshop Saturn Console Vulnerable to SQL Injection via ClusterKey ComponentCVE-2025-31727Mediumorg.codefirst.jenkins.asakusasatellite:asakusa-satellite-plugin: Jenkins AsakusaSatellite Plugin Stores API Keys Unencrypted in Job `config.xml` FilesCVE-2025-31726Mediumorg.jenkins-ci.plugins:stackhammer: Jenkins Stack Hammer Plugin Stores API Keys Unencrypted in Job `config.xml` Files

Stop the waste.
Protect your environment with Kodem.