VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

321 CVEsRSS

GHSA-48qw-824m-86prHigh· 7.7
2mo ago

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

▾ Twilightarcadedb · com.arcadedb:arcadedb-servervia GHSA
GHSA-x9f9-r4m8-9xc2High
2mo ago

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

▾ Twilightarcadedb · com.arcadedb:arcadedb-enginevia GHSA
GHSA-vwjc-v7x7-cm6gHigh
2mo ago

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

▾ Twilightarcadedb · com.arcadedb:arcadedb-enginevia GHSA
GHSA-x8mg-6r4p-87pfHigh
2mo ago

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

▾ Twilightarcadedb · com.arcadedb:arcadedb-servervia GHSA
CVE-2026-10051Medium· 5.3
2mo ago

jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051)

A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintention…

▾ SunlitRed Hat · Red Hat Satellite 6.17 for RHEL 9EPSS 0.30%via CSAF
CVE-2026-59889Medium· 6.5
2mo ago

com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE…

A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to w…

▾ SunlitRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.39%via CSAF
CVE-2026-59888Medium· 6.5
2mo ago

com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records (CVE…

A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
CVE-2026-59955High· 7.5
2mo ago

Apollo ConfigService access key authentication bypass via raw config file appId parsing

Apollo ConfigService access key authentication bypass via raw config file appId parsing

▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2026-59954High· 7.5
2mo ago

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2025-32781Medium· 6.5
2mo ago

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

▾ Sunlitctrip · com.ctrip.framework.apollo:apolloEPSS 0.41%via GHSA
CVE-2026-59899High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899)

A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. The HTTP decoder in netty-codec-http fails to properly limit the decompression of this content, causing t…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.61%via CSAF
CVE-2026-59901High· 7.5
2mo ago

io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) (CVE-2026-59901)

A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data …

▾ TwilightRed Hat · Red Hat build of Apache Camel - HawtIO 4EPSS 0.46%via CSAF
GHSA-387m-935m-c4vwHigh· 7.5
2mo ago

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

▾ Twilightmicronaut · io.micronaut:micronaut-http-clientvia GHSA
GHSA-q6gh-6v2r-hjv3Medium· 6.8
2mo ago

Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers

Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers

▾ Sunlitmicronaut · io.micronaut:micronaut-http-clientvia GHSA
CVE-2026-49485High· 7.5
2mo ago

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
GHSA-cgfv-jrfp-2r7vHigh
2mo ago

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

▾ Twilightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-54641High· 7.7
2mo ago

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

▾ Twilightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-54640High· 7.6
2mo ago

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

▾ Twilightopenremote · io.openremote:openremote-agentvia GHSA
CVE-2026-2092High· 7.7
2mo ago

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

▾ Twilightkeycloak · org.keycloak:keycloak-servicesEPSS 0.31%via GHSA
CVE-2026-9795High· 7.3
2mo ago

Keycloak has privilege escalation via improper scope mapping enforcement

Keycloak has privilege escalation via improper scope mapping enforcement

▾ Twilightkeycloak · org.keycloak:keycloak-servicesEPSS 0.49%via GHSA
CVE-2026-53712High
2mo ago

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

▾ Twilightongres · com.ongres.scram:scram-clientEPSS 0.26%via GHSA
GHSA-j6hm-v3x2-qv6jLow
2mo ago

land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory

land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory

▾ Sunlitoras · land.oras:oras-java-sdkvia GHSA
CVE-2026-39379High· 7.1
2mo ago

GeoNetwork has reflected XSS through client-side template injection

GeoNetwork has reflected XSS through client-side template injection

▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA
CVE-2026-46487High· 7.5
2mo ago

GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field

GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field

▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA
CVE-2026-46560High· 7.5
3mo ago

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

▾ Twilightopenidentityplatform · org.openidentityplatform.openam:openam-radiusvia GHSA
CVE-2026-57300Medium· 4.3
3mo ago

Jenkins MCP Server Plugin missing a permission check

Jenkins MCP Server Plugin missing a permission check

▾ Sunlitjenkins · io.jenkins.plugins:mcp-serverEPSS 0.28%via GHSA
CVE-2026-57301High· 8.8
3mo ago

Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE

Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE

▾ Twilightjenkins-ci · org.jenkins-ci.plugins:zapperEPSS 0.63%via GHSA
CVE-2026-57303High· 7.1
3mo ago

Jenkins Assembla Plugin has an XXE vulnerability

Jenkins Assembla Plugin has an XXE vulnerability

▾ Twilightjenkins-ci · org.jenkins-ci.plugins:assemblaEPSS 0.36%via GHSA
CVE-2026-57302Medium· 4.3
3mo ago

Jenkins FitNesse Plugin stores passwords unencrypted

Jenkins FitNesse Plugin stores passwords unencrypted

▾ Sunlitjenkins-ci · org.jenkins-ci.plugins:fitnesseEPSS 0.28%via GHSA
CVE-2026-57306Medium· 4.2
3mo ago

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

▾ Sunlitjenkins · io.jenkins.plugins:zdevopsEPSS 0.18%via GHSA
CVEs tagged “maven” — page 7 · VulnSea