Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-32068Mediumorg.xwiki.platform:xwiki-platform-oldcore: org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerabilityCVE-2022-47937Criticalorg.apache.sling:org.apache.sling.commons.json: Apache Sling Commons JSON bundle vulnerable to Improper Input ValidationCVE-2023-32081Mediumio.vertx:vertx-stomp: Vert.x STOMP server process client frames that would not send initially a connect frameCVE-2024-23689Mediumcom.clickhouse:clickhouse-client: ClickHouse vulnerable to client certificate password exposure in client exceptionCVE-2023-29032Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings Improper Authentication vulnerabilityCVE-2023-29246Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings vulnerable to remote code execution via null-bye injectionCVE-2023-32070Criticalorg.xwiki.rendering:xwiki-rendering-syntax-xhtml: Improper Neutralization of Script in Attributes in XWiki (X)HTML renderersCVE-2023-32069Criticalorg.xwiki.platform:xwiki-platform-test-ui: Privilege escalation (PR)/RCE from account through class sheetCVE-2023-31141Mediumorg.opensearch.plugin:opensearch-security: OpenSearch issue with fine-grained access control during extremely rare race conditionsCVE-2023-31126Criticalorg.xwiki.commons:xwiki-commons-xml: Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xmlCVE-2023-32071Criticalorg.xwiki.platform:xwiki-platform-distribution-war: XWiki Platform vulnerable to RXSS via editor parameter - importinline templateCVE-2020-22755Highnet.mingsoft:ms-mcms: MCMS vulnerable to arbitrary code execution via crafted thumbnailCVE-2021-40331Highorg.apache.ranger:ranger-hive-plugin: Apache Ranger Hive Plugin missing permissions checkCVE-2023-30093Mediumorg.onosproject:onos-archetypes: ONOS vulnerable to Cross-site ScriptingCVE-2023-30331Criticalcom.ibeetl:beetl: Server-side template injection in beetlCVE-2023-25827Highnet.opentsdb:opentsdb: Cross Site Scripting in OpenTSDBCVE-2023-25826Criticalnet.opentsdb:opentsdb: Command injection in OpenTSDBCVE-2023-32007Highorg.apache.spark:spark-parent_2.12: Apache Spark UI vulnerable to Command InjectionCVE-2022-45801Mediumorg.apache.streampark:streampark: Apache StreamPark LDAP Injection vulnerabilityGHSA-JGVC-JFGH-RJVVMediumorg.bitbucket.b_c:jose4j: Chosen Ciphertext Attack in Jose4jCVE-2023-29471Mediumcom.typesafe.akka:akka-stream-kafka_3: Lightbend Alpakka Kafka logs credentials on debug levelCVE-2023-30349Criticalcom.jflyfox:jflyfox_jfinal: Remote code execution in JFinal CMSCVE-2023-22665Mediumorg.apache.jena:jena: Arbitrary javascript injection in Apache JenaCVE-2023-29924Criticaltech.powerjob:powerjob: PowerJob vulnerable to incorrect access controlCVE-2023-29525Criticalorg.xwiki.platform:xwiki-platform-distribution-war: XWiki Platform vulnerable to privilege escalation from view right on XWiki.Notifications.Code.LegacyNotificationAdministration

Stop the waste.
Protect your environment with Kodem.