Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-27162Criticalorg.openapitools:openapi-generator-project: OpenAPI Generator vulnerable to Server-Side Request ForgeryCVE-2023-1784Criticalorg.jeecgframework.boot:jeecg-boot-parent: jeecg-boot vulnerable to improper authentication CVE-2023-1741Criticalorg.jeecgframework.boot:jeecg-boot-parent: jeecg-boot vulnerable to SQL injectionCVE-2023-28462Criticalfish.payara.server:payara-aggregator: Payara Server allows remote attackers to load malicious code on the server once a JNDI directory scan is performedCVE-2023-28935Highorg.apache.uima:uima-ducc-parent: Apache UIMA DUCC allows remote code execution CVE-2023-28158Mediumorg.apache.archiva:archiva: Apache Archiva vulnerable to privilege escalation via stored cross-site scripting (XSS)CVE-2023-25721Mediumcom.veracode.jenkins:veracode-scan: Veracode Scan Jenkins Plugin vulnerable to information disclosureCVE-2023-25722Mediumcom.veracode.jenkins:veracode-scan: Veracode Scan Jenkins Plugin vulnerable to information disclosureCVE-2023-28326Criticalorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings missing authentication and can allow user impersonation CVE-2023-20860Criticalorg.springframework:spring: Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatchCVE-2023-28628Mediumlambdaisland:uri: lambdaisland/uri `authority-regex` returns the wrong authorityCVE-2023-28640Mediumio.apiman:apiman-manager-api-rest-impl: Apiman vulnerable to permissions bypass due to missing check on API key URLCVE-2023-27096Mediumcn.hippo4j:hippo4j-all: Hippo4j allows attacker to obtain sensitive info via ConfigVerifyController function of Tenant Management moduleCVE-2023-27296Highorg.apache.inlong:inlong-manager: Apache InLong vulnerable to JDBC Deserialization of Untrusted DataCVE-2023-28867Highcom.graphql-java:graphql-java: GraphQL Java vulnerable to stack consumptionCVE-2023-20861Mediumorg.springframework:spring-expression: Spring Framework vulnerable to denial of service via specially crafted SpEL expressionCVE-2023-20859Mediumorg.springframework.vault:spring-vault-core: Spring Vault vulnerable to insertion of sensitive information into a log fileCVE-2023-1370Highnet.minidev:json-smart: json-smart Uncontrolled Recursion vulnerabilityCVE-2023-27094Highcn.hippo4j:hippo4j-all: Hippo4j privilege escalation issueCVE-2023-0870Mediumorg.opennms:opennms-webapp: OpenNMS Meridian and Horizon vulnerable to Cross-Site Request ForgeryCVE-2023-28708Mediumorg.apache.tomcat:tomcat-catalina: Apache Tomcat vulnerable to Unprotected Transport of CredentialsCVE-2023-1436Highorg.codehaus.jettison:jettison: Jettison vulnerable to infinite recursionCVE-2023-27087Highcom.xuxueli:xxl-job: Xuxueli xxl-job allows attacker to obtain sensitive information via the pageList parameterCVE-2023-28118Highcom.charleskorn.kaml:kaml: kaml has potential denial of service while parsing input with anchors and aliases CVE-2023-26513Highorg.apache.sling:org.apache.sling.resourcemerger: Apache Sling Resource Merger has Excessive Iteration vulnerability

Stop the waste.
Protect your environment with Kodem.