boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Maven

Package ecosystem Maven. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDPackages affected
331327199

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅▅█▂

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 2 · 2026-03 1 · 2026-04 5 · 2026-05 15 · 2026-06 49 · 2026-07 67 · 2026-08 61 · 2026-09 113 · 2026-10 13

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-4660410.0100.0KEVApache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization caus…
CVE-2026-341978.896.7KEVApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could…
CVE-2025-684938.198.8—Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
CVE-2026-438257.396.4—Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
CVE-2026-448259.886.2—Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVE-2026-400479.183.7—Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables ar…
CVE-2026-408609.873.9—Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, cam…
CVE-2026-410429.173.6—Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through th…
CVE-2026-23329.169.5—HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
CVE-2026-420279.868.8—Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
CVE-2026-506338.168.8—Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
CVE-2026-408588.867.8—Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
CVE-2026-274469.366.6—Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
CVE-2026-669099.865.7—Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
CVE-2026-506328.164.9—Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory
CVE-2026-526809.864.8—Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
CVE-2026-539139.864.1—Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only ins…
CVE-2026-579679.863.7—Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol sessio…
CVE-2026-424407.563.5—Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
CVE-2026-559769.162.7—Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation…

Most-affected packages

Packages with the most advisories
PackageCVEs
org.apache.activemq:apache-activemq17
org.apache.activemq:activemq-all14
org.apache.dolphinscheduler:dolphinscheduler-api14
org.apache.activemq:activemq-broker11
org.apache.cxf:cxf-rt-rs-security-oauth211
org.apache.thrift:libthrift9
org.apache.wicket:wicket-core9
org.apache.neethi:neethi8
org.apache.storm:storm-server8
org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol7
org.apache.qpid:proton-j6
org.apache.syncope.core:syncope-core-spring6
com.vaadin:vaadin5
org.apache.activemq:artemis-server5
org.apache.artemis:artemis-server5