Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-2321Mediumorg.wso2.am:am-parent: WSO2 incorrect authorization vulnerabilityCVE-2025-1634Highio.quarkus:quarkus-resteasy: io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests TimeoutCVE-2025-1584Mediumorg.noear:solon-web-staticfiles: Solon Path TraversalCVE-2025-24893Criticalorg.xwiki.platform:xwiki-platform-search-solr-ui: XWiki Platform allows remote code execution as guest via SolrSearchMacros requestCVE-2025-23020Mediumtech.kwik:kwik: Kwik hash collision vulnerabilityCVE-2024-4028Loworg.keycloak:keycloak-core: Keycloak allows cross-site scripting (XSS)CVE-2024-56180Criticalorg.apache.eventmesh:eventmesh-meta-raft: Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code executionCVE-2024-52577Criticalorg.apache.ignite:ignite-core: Apache Ignite: Possible RCE when deserializing incoming messages by the server nodeCVE-2025-26511Highcom.instaclustr:cassandra-lucene-index-plugin: Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBACCVE-2025-1247Highio.quarkus:quarkus-rest: Quarkus REST Endpoint Request Parameter Leakage Due to Shared InstanceCVE-2024-46910Mediumorg.apache.atlas:apache-atlas: Apache Atlas: An authenticated user can perform XSS and potentially impersonate another userCVE-2024-32037Mediumorg.geonetwork-opensource:gn-services: GeoNetwork search end-point information disclosure in response headersCVE-2024-52067Mediumorg.apache.nifi:nifi-framework-core: Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug LogCVE-2025-25193Mediumio.netty:netty-common: Denial of Service attack on windows app using NettyCVE-2025-24970Highio.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngineCVE-2025-25247Mediumorg.apache.felix:org.apache.felix.webconsole: Apache Felix Webconsole: XSS in services consoleCVE-2024-57606Highorg.jeecgframework.boot:jeecg-boot-common: SQL injection in JeecgBootCVE-2024-45626Highorg.apache.james:james-server-jmap-draft: Apache James vulnerable to denial of service through JMAP HTML to text conversionCVE-2024-37358Highorg.apache.james.protocols:protocols-imap: Apache James vulnerable to denial of service through the use of IMAP literalsCVE-2024-57699Highnet.minidev:json-smart: Netplex Json-smart Uncontrolled Recursion vulnerabilityCVE-2024-10973Mediumorg.keycloak:keycloak-quarkus-server: Keycloak on Quarkus CLI option for encrypted JGroups ignoredCVE-2024-36404Criticalorg.geotools:gt-app-schema: GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressionsCVE-2025-24860Mediumorg.apache.cassandra:cassandra-all: Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regionsCVE-2024-27137Mediumorg.apache.cassandra:cassandra-all: Apache Cassandra: unrestricted deserialization of JMX authentication credentialsCVE-2025-23015Highorg.apache.cassandra:cassandra-all: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions

Stop the waste.
Protect your environment with Kodem.