Vendor Intelligence

maven

33 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-55772 · CVSS 8.8

CedarJava has type confusion vulnerability

View CVE report →
CVE-2026-55773 · CVSS 8.8

CedarJava has policy injection vulnerability

View CVE report →
CVE-2026-40076 · CVSS 8.7

OpenMRS Module Upload Vulnerable to Path Traversal (Zip Slip)

View CVE report →
CVE-2026-45674 · CVSS 8.7

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

View CVE report →
CVE-2026-47691 · CVSS 8.7

Netty has Insufficient Bailiwick Validation for NS Records

View CVE report →
CVE-2026-44795 · CVSS 8.5

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

View CVE report →
CVE-2026-45048 · CVSS 8.5

OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC

View CVE report →
CVE-2026-45049 · CVSS 8.3

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

View CVE report →
CVE-2026-46481 · CVSS 8.3

OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users

View CVE report →
CVE-2026-39852 · CVSS 8.2

Quarkus has Authentication/Authorization bypasses

View CVE report →
CVE-2026-44249 · CVSS 8.1

Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking

View CVE report →
CVE-2026-44900 · CVSS 8.1

epa4all-client has a VAU Signature bypass

View CVE report →
CVE-2026-45574 · CVSS 8.1

epa4all-client: TLS Certificate Validation Disabled in Production

View CVE report →
CVE-2026-49464 · CVSS 8.1

NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak

View CVE report →
CVE-2026-54076 · CVSS 8.1

ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)

View CVE report →
CVE-2026-54512 · CVSS 8.1

jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation

View CVE report →
CVE-2026-54513 · CVSS 8.1

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

View CVE report →
CVE-2026-11400 · CVSS 8

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

View CVE report →
CVE-2026-49832 · CVSS 8

DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN

View CVE report →
CVE-2025-53114 · CVSS 7.5

Acknowledgement extension out of memory

View CVE report →
CVE-2026-34151 · CVSS 7.5

XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+

View CVE report →
CVE-2026-40075 · CVSS 7.5

OpenMRS ModuleResourcesServlet has Path Traversal that Leads to Arbitrary File Read

View CVE report →
CVE-2026-41573 · CVSS 7.5

OpenAM has LDAP Injection via `_queryId` Parameter

View CVE report →
CVE-2026-42577 · CVSS 7.5

Netty epoll transport denial of service via RST on half-closed TCP connection

View CVE report →
CVE-2026-44891 · CVSS 7.5

Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder

View CVE report →
CVE-2026-44894 · CVSS 7.5

Netty's Default QUIC token handler accepts any client-supplied token

View CVE report →
CVE-2026-46487 · CVSS 7.5

GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field

View CVE report →
CVE-2026-47695 · CVSS 7.5

CC-Tweaked has an SSRF Protection Bypass with NAT64

View CVE report →
CVE-2026-48048 · CVSS 7.5

XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests

View CVE report →
CVE-2026-45575 · CVSS 7.4

Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-client

View CVE report →
CVE-2025-27511 · CVSS 7.2

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

View CVE report →
CVE-2026-45609 · CVSS 7.2

Spring AI MCP Security: Unvalidated URL Fetching (SSRF)

View CVE report →
CVE-2026-54077 · CVSS 7.1

ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users

View CVE report →