VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

276 CVEsRSS

CVE-2026-55846Medium· 6.2PoC
1w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer() in allure-commandline/src/ma…

Twilightallure-framework · allure2EPSS 0.15%via NVD
CVE-2026-55847Medium· 6.1
1w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTra…

Sunlitallure-framework · allure2EPSS 0.24%via NVD
CVE-2026-11748Medium
1w ago

Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion

Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion

Sunlitlinecorp · com.linecorp.centraldogma:centraldogma-server-auth-shiroEPSS 0.62%via GHSA
CVE-2026-49463Medium· 6.5
1w ago

NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `n…

Sunlitnl-portal · nl.nl-portal:besluitenEPSS 0.32%via CVEORG
CVE-2026-49464High· 8.1
1w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to …

Twilightnl-portal · nl-portal-backend-librariesEPSS 0.20%via NVD
CVE-2026-49439Medium· 4.3
1w ago

OpenRemote is an open-source internet-of-things platform

OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.

Sunlitopenremote · openremoteEPSS 0.16%via NVD
CVE-2026-49832High· 8.0
2w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible …

Twilightdspace · org.dspace:dspace-apiEPSS 0.54%via NVD
CVE-2026-49831Medium· 5.5
2w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r param…

Sunlitdspace · org.dspace:dspace-apiEPSS 0.35%via NVD
CVE-2026-49830Medium· 4.4
2w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the …

Sunlitdspace · org.dspace:dspace-apiEPSS 0.41%via NVD
CVE-2026-49833Medium· 5.5
2w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, and 10-rc1 to before 10.0, a path traversal vulnerability is possible…

Sunlitdspace · org.dspace:dspace-apiEPSS 0.27%via NVD
CVE-2026-55848High· 8.6
3w ago

mapfish-print is a component of MapFish for printing templated cartographic maps

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print end…

Twilightmapfish · org.mapfish.print:print-libEPSS 0.33%via NVD
CVE-2026-55856Medium· 5.9
3w ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a pa…

Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.22%via NVD
CVE-2026-55857Medium· 5.9
3w ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insec…

Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.20%via NVD
CVE-2026-55858Medium· 5.9
3w ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the a…

Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.34%via NVD
CVE-2026-55859Medium· 5.9
3w ago

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A s…

Sunlitmariadb · org.mariadb:r2dbc-mariadbEPSS 0.30%via NVD
CVE-2026-55860Medium· 5.9
3w ago

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the Authentication…

Sunlitmariadb · org.mariadb:r2dbc-mariadbEPSS 0.15%via NVD
CVE-2026-55841High· 7.5
3w ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/c…

Twilightgraylog2 · org.graylog2:graylog2-serverEPSS 0.36%via NVD
CVE-2026-55867Medium
3w ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog…

Sunlitgraylog2 · org.graylog2:graylog2-serverEPSS 0.34%via NVD
CVE-2026-55673High
3w ago

PowSyBl (Power System Blocks) is a framework to build power system oriented software

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpret…

Twilightpowsybl · com.powsybl:powsybl-computation-localEPSS 0.43%via NVD
CVE-2026-55559Critical· 9.8
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templat…

Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.55%via NVD
CVE-2026-55565Critical· 9.9
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source c…

Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.46%via NVD
CVE-2026-55566Medium· 4.3
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component…

Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.27%via NVD
CVE-2026-55425Medium· 5.0
3w ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleSe…

Sunlitgraylog2 · org.graylog2:graylog2-serverEPSS 0.30%via NVD
CVE-2026-55511Critical· 9.1PoC
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fil…

Abyssalyamcs · org.yamcs:yamcs-coreEPSS 0.68%via NVD
CVE-2026-55521High· 8.8
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and T…

Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.36%via NVD
CVE-2026-55545Medium· 6.5
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic…

Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.33%via NVD
CVE-2026-55547Medium· 4.3
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.jav…

Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.25%via NVD
CVE-2026-55549Medium· 6.5PoC
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping b…

Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.90%via NVD
CVE-2026-55552High· 7.5
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the…

Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.43%via NVD
CVE-2026-54556High
3w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in ember-core/shared/s…

Twilighthttp4s · org.http4s:http4s-ember-core_2.12EPSS 0.30%via NVD
CVEs tagged “maven” — page 3 · VulnSea