Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47065Criticalorg.apache.mina:mina-core: Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClassCVE-2026-46718Mediumorg.apache.calcite:calcite-core: Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select ClassesCVE-2026-40990Mediumorg.springframework.cloud:spring-cloud-function-context: Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function RegistryCVE-2026-40989Mediumorg.springframework.cloud:spring-cloud-function-context: Spring Cloud Function Context has Uncontrolled RecursionCVE-2026-10532Lowch.qos.logback:logback-core: Logback vulnerable to Object Injection through HardenedObjectInputStream modulesCVE-2026-49328Mediumorg.apache.fesod:fesod-sheet: Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter componentCVE-2026-46605Mediumorg.apache.activemq:apache-activemq: Apache ActiveMQ server has an incomplete authorization workflowCVE-2026-49270Mediumorg.apache.activemq:apache-activemq: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerabilityCVE-2026-49157Highorg.apache.activemq:apache-activemq: Apache ActiveMQ has an Incorrect Default Permissions vulnerabilityCVE-2026-48827Highorg.apache.sshd:sshd-git: Apache MINA SSHD bundle sshd-git has a path traversal vulnerabilityCVE-2026-49361Highorg.apache.fluss:fluss-common: Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServerCVE-2026-45505Highorg.apache.activemq:activemq-broker: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issueCVE-2026-42588Highorg.apache.activemq:activemq-broker: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issueCVE-2026-42253Mediumorg.apache.activemq:apache-activemq: Apache ActiveMQ, Apache ActiveMQ Web have a Cross-site Scripting issueCVE-2026-44825Highorg.apache.solr:solr-core: Apache Solr has hardcoded credentials in the Basic Authentication setup toolCVE-2026-35563Highorg.apache.directory.api:api-ldap-client-api: Apache Directory LDAP API lacks server certificate verification for LDAP hostnamesCVE-2026-47695Highcc.tweaked:cc-tweaked-1.21-core: CC-Tweaked has an SSRF Protection Bypass with NAT64CVE-2026-9828Lowch.qos.logback:logback-core: QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerabilityCVE-2026-40914Mediumorg.apache.artemis:artemis-stomp-protocol: Apache Artemis has an Incorrect Authorization issueCVE-2025-48977Highorg.apache.ignite:ignite-core: Apache Ignite REST API Has a Relative Path Traversal VulnerabilityCVE-2026-9803Mediumorg.keycloak:keycloak-services: Keycloak has an Out-of-bounds ReadCVE-2026-9802Mediumorg.keycloak:keycloak-services: Keycloak has Insufficient Session ExpirationCVE-2026-9801Mediumorg.keycloak:keycloak-ldap-federation: Keycloak Vulnerable to Improper Validation of Specified Quantity in InputCVE-2026-9798Mediumorg.keycloak:keycloak-services: Keycloak has an Authentication Bypass by Primary WeaknessCVE-2026-9793Mediumorg.keycloak:keycloak-services: Keycloak has an Improper Verification of Cryptographic Signature issue

Stop the waste.
Protect your environment with Kodem.