CVE Tools

Maven

5,667 CVEs tracked since 2000. Since Jul 2021, 19 of them reached CISA KEV.

Maven CVEs per month

Jul 2021 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Maven CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-07280
2021-08511
2021-09260
2021-10270
2021-11460
2021-12312
2022-01750
2022-02890
2022-03881
2022-04583
2022-05770
2022-061120
2022-07751
2022-08641
2022-091080
2022-10730
2022-11930
2022-12560
2023-01780
2023-02480
2023-03null or fewer
2023-04940
2023-05992
2023-06860
2023-07860
2023-08580
2023-09590
2023-10812
2023-11650
2023-121170
2024-01621
2024-02890
2024-03670
2024-04501
2024-05290
2024-06310
2024-07481
2024-08270
2024-09380
2024-10440
2024-11480
2024-12390
2025-01430
2025-02271
2025-03641
2025-04560
2025-05350
2025-06580
2025-07690
2025-08810
2025-09900
2025-101030
2025-11301
2025-12480
2026-01530
2026-02390
2026-03230
2026-0490
2026-0570
2026-06120
2026-07190

Products

The products that kept showing up in Maven's monthly top three, with their CVEs summed over those months.

  1. Com.liferay.portal:release.portal.bom1178 months
  2. Com.liferay.portal:release.dxp.bom9610 months
  3. Org.keycloak:keycloak-services4210 months
  4. Org.jenkins-ci.main:jenkins-core366 months
  5. Com.jfinal:jfinal312 months
  6. Com.thoughtworks.xstream:xstream141 month
  7. Org.xwiki.platform:xwiki-platform-oldcore133 months
  8. Org.geoserver.web:gs-web-app113 months
  9. Com.liferay.portal:com.liferay.portal.impl102 months
  10. Org.apache.inlong:manager-pojo102 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Maven.

  1. GHSA-fp43-vj7g-pg92OmniFaces: Forged combined-resource IDs and related output/push boundaries—
  2. GHSA-7ppr-r889-mcf2blaze: Unbounded WebSocket message aggregation in http4s-blaze-server—
  3. GHSA-46q4-43ph-c6frblaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)—
  4. GHSA-mhvj-jhpq-885vblaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser—
  5. GHSA-p279-2cqp-84jgOpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check—
  6. GHSA-68r5-9hpg-7qw9OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway—
  7. GHSA-v74w-7mr3-4qg3Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion—
  8. GHSA-mfg7-5gfp-c4w3Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names—
  9. GHSA-464c-974j-9xm6AWS CDK CodeBuild S3 Log Encryption Boolean Inversion—
  10. GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)—
  11. GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`—
  12. GHSA-x8mg-6r4p-87pfArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization—
  13. GHSA-vwjc-v7x7-cm6gArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js—
  14. GHSA-x9f9-r4m8-9xc2ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)—
  15. GHSA-48qw-824m-86prArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read—

The record

Peak rank
#3 in Dec 2023
Busiest month shown
Dec 2023, 117 CVEs
Months with a KEV entry
14 since Jul 2021
Monthly snapshots
213 since 2000
Maven's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store