Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-0148Lowio.jenkins.plugins:zoom: Jenkins Zoom Plugin is Missing Password Field MaskingCVE-2025-24961Mediumorg.gaul:s3proxy: S3Proxy allows insecure path traversal in filesystem and filesystem-nio2 storage backendsCVE-2025-23367Mediumorg.wildfly.core:wildfly-server: WildFly improper RBAC permissionCVE-2025-23215Criticalnet.sourceforge.pmd:pmd-designer: PMD Designer's release key passphrase (GPG) available on Maven Central in cleartextCVE-2025-0142Mediumio.jenkins.plugins:zoom: Jenkins Zoom Plugin Stores Sensitive Information in CleartextGHSA-VPXM-CR3R-PJP9Criticalorg.openmrs:openmrs: General OpenMRS Security Advisory, January 2025: Penetration Testing Results and PatchesCVE-2025-0851Criticalai.djl:api: Deep Java Library path traversal issueCVE-2025-24790Mediumnet.snowflake:snowflake-jdbc: Snowflake JDBC uses insecure temporary credential cache file permissionsCVE-2025-24789Highnet.snowflake:snowflake-jdbc: Snowflake JDBC allows an untrusted search path on WindowsCVE-2024-57436Highcom.ruoyi:ruoyi: RuoYi allowed unauthorized attackers to view the session ID of the admin in the system monitoringCVE-2024-57439Mediumcom.ruoyi:ruoyi: RuoYi vulnerable to Denial of Service by attackers with admin privilegesCVE-2024-57438Mediumcom.ruoyi:ruoyi: RuoYi has insecure permissionsCVE-2024-29869Mediumorg.apache.hive:hive-exec: Apache Hive Incorrectly Assigns Permissions for a Critical ResourceCVE-2025-0736Mediumorg.infinispan:infinispan-parent: Infinispan vulnerable to Insertion of Sensitive Information into Log FileCVE-2024-23953Mediumorg.apache.hive:hive-llap-common: Apache Hive vulnerable to Observable Timing Discrepancy and Authentication Bypass by SpoofingCVE-2025-24783Loworg.apache.cocoon:cocoon-forms-impl: Apache Cocoon vulnerable to Incorrect Usage of Seeds in Pseudo-Random Number GeneratorCVE-2024-52012Mediumorg.apache.solr:solr-core: Apache Solr Relative Path Traversal vulnerabilityCVE-2025-24814Highorg.apache.solr:solr-core: Apache Solr vulnerable to Execution with Unnecessary PrivilegesCVE-2025-24363Mediumorg.hl7.fhir.publisher:org.hl7.fhir.publisher.core: HL7 FHIR IG Publisher potentially exposes GitHub repo user and credential informationCVE-2024-52807Highorg.hl7.fhir.publisher:org.hl7.fhir.publisher.cli: XXE vulnerability in XSLT parsing in `org.hl7.fhir.publisher`CVE-2024-53299Mediumorg.apache.wicket:wicket-core: Apache Wicket: An attacker can intentionally trigger a memory leakCVE-2024-56923Mediumorg.silverpeas.core:silverpeas-core: Cross site scripting in Silverpeas CoreCVE-2025-24403Mediumorg.jenkins-ci.plugins:service-fabric: Missing permission checks in Jenkins Azure Service Fabric Plugin CVE-2025-24401Mediumio.jenkins.plugins:folder-auth: Disabled permissions can be granted by Folder-based in Jenkins Authorization Strategy PluginCVE-2025-24402Mediumorg.jenkins-ci.plugins:service-fabric: CSRF vulnerability in Jenkins Azure Service Fabric Plugin

Stop the waste.
Protect your environment with Kodem.