Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-35143Mediumjenkins:repository: Stored XSS vulnerability in Jenkins Maven Repository Server PluginCVE-2023-34396Highorg.apache.struts:struts2-core: Apache Struts vulnerable to memory exhaustionCVE-2023-34149Mediumorg.apache.struts:struts2-core: Apache Struts vulnerable to memory exhaustionCVE-2023-33695Highcn.hutool:hutool-core: Insecure Temporary File in HuToolCVE-2023-34468Highorg.apache.nifi:nifi-dbcp-base: Apache NiFi vulnerable to Code InjectionCVE-2023-34212Mediumorg.apache.nifi:nifi-jms-processors: Apache NiFi vulnerable to Deserialization of Untrusted DataCVE-2023-35042Criticalorg.geoserver:gs-wms: GeoServer RCE due to improper control of generation of code in jai-ext`Jiffle` map algebra languageCVE-2023-3163Lowcom.ruoyi:ruoyi: RuoYi Uncontrolled Resource Consumption vulnerabilityCVE-2023-33496Criticalcom.xuxueli:xxl-rpc-core: xxl-rpc deserialization vulnerabilityCVE-2023-33510Highorg.jeecgframework.p3:jeecg-p3-biz-chat: Jeecg P3 Biz Chat allows remote attackers to read arbitrary filesCVE-2023-33962Mediumio.jstach:jstachio: JStachio XSS vulnerability: Unescaped single quotesCVE-2023-32310Highio.dataease:dataease-plugin-common: DataEase API interface has IDOR vulnerabilityCVE-2023-33546Mediumorg.codehaus.janino:janino-parent: janino vulnerable to denial of service due to stack overflowCVE-2023-33544Mediumio.hawt:project: hawtio vulnerable to Path TraversalCVE-2023-33779Highcom.xuxueli:xxl-job: Privilege escalation in XXL-JobCVE-2023-20883Highorg.springframework.boot:spring-boot-autoconfigure: Spring Boot Welcome Page Denial of ServiceCVE-2023-2798Highorg.htmlunit:htmlunit: Unrestricted recursion in htmlunitCVE-2022-46907Mediumorg.apache.jspwiki:jspwiki-main: Apache JSPWiki vulnerable to cross-site scripting on several pluginsCVE-2023-33949Mediumcom.liferay.portal:release.portal.bom: Insecure Default Initialization In Liferay PortalCVE-2023-33950Mediumcom.liferay.portal:release.portal.bom: Liferay Portal has Inefficient Regular ExpressionCVE-2023-33944Mediumcom.liferay.portal:release.portal.bom: Cross-site scripting in Liferay PortalCVE-2023-33948Highcom.liferay.portal:release.portal.bom: Missing authorization in Liferay portalCVE-2023-33946Mediumcom.liferay.portal:release.portal.bom: Liferay portal unauthorized access to objects via OAuth 2 scopeCVE-2023-33947Mediumcom.liferay.portal:release.portal.bom: Liferay portal has unauthorized access to object definition via search CVE-2023-33945Highcom.liferay.portal:release.portal.bom: SQL injection in Liferay Portal

Stop the waste.
Protect your environment with Kodem.