Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-24400Mediumcom.axis.jenkins.plugins.eiffel:eiffel-broadcaster: Cache confusion in Jenkins Eiffel Broadcaster Plugin CVE-2025-24397Mediumorg.jenkins-ci.plugins:gitlab-plugin: Incorrect permission check in Jenkins GitLab Plugin allows enumerating credentials IDs CVE-2025-24399Highorg.jenkins-ci.plugins:oic-auth: Improper handling of case sensitivity in Jenkins OpenId Connect Authentication Plugin CVE-2025-24398Highio.jenkins.plugins:atlassian-bitbucket-server-integration: Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URLCVE-2024-45479Criticalorg.apache.ranger:ranger: Apache Ranger UI vulnerable to Server Side Request ForgeryCVE-2024-45478Mediumorg.apache.ranger:ranger: Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service PageCVE-2024-43709Mediumorg.elasticsearch:elasticsearch: Elasticsearch allocation of resources without limits or throttling leads to crashCVE-2025-23184Highorg.apache.cxf:cxf-core: Apache CXF: Denial of Service vulnerability with temporary filesCVE-2025-23366Mediumorg.jboss.hal:hal-console: HAL Console has a Cross Site Scripting (XSS) vulnerability of user inputCVE-2023-0482Mediumorg.jboss.resteasy:resteasy-core: Insecure Temporary File in RESTEasyCVE-2024-45627Mediumorg.apache.linkis:linkis-metadata-query-service-jdbc: Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerabilityCVE-2025-23025Criticalorg.xwiki.platform:xwiki-platform-realtime-wysiwyg-ui: XWiki Realtime WYSIWYG Editor extension allows privilege escalation (PR) through realtime WYSIWYG editingCVE-2024-11734Mediumorg.keycloak:keycloak-quarkus-server: Denial of Service in Keycloak Server via Security HeadersCVE-2024-11736Mediumorg.keycloak:keycloak-quarkus-server: Keycloak allows unrestricted admin use of system and environment variablesCVE-2025-23026Mediumgg.jte:jte: jte's HTML templates containing Javascript template strings are subject to XSSCVE-2024-54676Criticalorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings vulnerable to Deserialization of Untrusted Data CVE-2024-8447Mediumorg.jboss.narayana.rts:lra-coordinator-jar: Narayana deadlock via multiple join requests sent to LRA CoordinatorCVE-2024-56512Loworg.apache.nifi:nifi-web-api: Apache NiFi: Missing Complete Authorization for Parameter and Service ReferencesCVE-2024-12744Highcom.amazon.redshift:redshift-jdbc42: Amazon Redshift JDBC Driver vulnerable to SQL InjectionCVE-2024-52046Criticalorg.apache.mina:mina-core: Apache MINA Deserialization RCE VulnerabilityCVE-2024-43441Criticalorg.apache.hugegraph:hugegraph-server: Apache HugeGraph-Server: Fixed JWT Token (Secret)GHSA-64GP-R758-8PFMMediumorg.jboss.hal:hal-console: Cross Site Scripting (XSS) vulnerability while uploading content to a new deploymentCVE-2024-23945Highorg.apache.hive:hive-service: Apache Hive and Spark: CookieSigner exposes the correct signature when message verification failsCVE-2024-56337Highorg.apache.tomcat:tomcat-catalina: Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityCVE-2024-38819Highorg.springframework:spring-webflux: Spring Framework Path Traversal vulnerability

Stop the waste.
Protect your environment with Kodem.