VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

276 CVEsRSS

CVE-2026-54251High· 8.7
6d ago

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequest…

Twilightnetty · netty-incubator-codec-ohttpEPSS 0.29%via NVD
CVE-2026-53966High· 7.1
6d ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document…

Twilightxwiki · xwiki-platformEPSS 0.33%via NVD
CVE-2026-53660High· 7.4
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and O…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-62263Critical· 9.2
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only …

MidnightOpenIdentityPlatform · OpenAMEPSS 0.55%via NVD
CVE-2026-62280Medium· 6.1
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl wi…

SunlitOpenIdentityPlatform · OpenAMEPSS 0.21%via NVD
CVE-2026-62379Critical· 9.8
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUti…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.65%via NVD
CVE-2026-54077High· 7.1
6d ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integrat…

TwilightArcadeData · arcadedbEPSS 0.37%via NVD
CVE-2026-54076High· 8.1
6d ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcad…

TwilightArcadeData · arcadedbEPSS 0.41%via NVD
CVE-2026-47424High· 7.5
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.35%via NVD
CVE-2026-47426High· 7.6
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to …

TwilightOpenIdentityPlatform · OpenAMEPSS 0.40%via NVD
CVE-2026-48717Critical· 9.1
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization co…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-55225High· 8.0
6d ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator wat…

Twilightstrimzi · strimzi-kafka-operatorEPSS 0.19%via NVD
CVE-2026-55226Medium· 5.4
6d ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom res…

Sunlitstrimzi · strimzi-kafka-operatorEPSS 0.18%via NVD
CVE-2026-41573High· 7.1
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protectio…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.36%via NVD
CVE-2026-44202Medium· 5.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrativ…

SunlitOpenIdentityPlatform · OpenAMEPSS 0.32%via NVD
CVE-2026-44203High· 8.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.47%via NVD
CVE-2026-44793High· 7.0
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 clust…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.45%via NVD
CVE-2026-46495Critical· 9.2
6d ago

OpenDJ is an LDAPv3 compliant directory service

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authen…

MidnightOpenIdentityPlatform · OpenDJEPSS 0.73%via NVD
CVE-2026-45048High· 8.5
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries s…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.25%via NVD
CVE-2026-46619Critical· 9.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.58%via NVD
CVE-2026-46623High· 7.4
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.49%via NVD
CVE-2026-45051Critical· 9.2
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInp…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.51%via NVD
CVE-2026-45052Critical· 9.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into …

MidnightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-45794High· 7.7
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.52%via NVD
CVE-2026-46498High· 7.6
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.32%via NVD
CVE-2026-48722Medium· 5.5
6d ago

Nextflow is a DSL for data-driven computational pipelines

Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.…

Sunlitnextflow-io · nextflowEPSS 0.10%via NVD
CVE-2026-53659High· 7.5
1w ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompress…

Twilighthttp4k · http4kEPSS 0.44%via NVD
CVE-2026-53752High· 7.5
1w ago

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn sty…

Twilightplutext · docx4jEPSS 0.44%via NVD
CVE-2026-50270High· 7.5
1w ago

dd-trace-java is a Datadog APM client for Java

dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply…

TwilightDataDog · dd-trace-javaEPSS 0.56%via NVD
CVE-2026-34151High· 8.2
1w ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix w…

Twilightxwiki · xwiki-platformEPSS 0.54%via NVD
CVEs tagged “maven” — page 2 · VulnSea