Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-46877Highcom.fasterxml.jackson.core:jackson-databind: jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNodeCVE-2023-1454Criticalorg.jeecgframework.boot:jeecg-boot-common: jeecg-boot SQL Injection vulnerabilityCVE-2023-27095Mediumcn.hippo4j:hippo4j-core: Exposure of Sensitive Information in OpenGoofy Hippo4jCVE-2023-0100Highorg.eclipse.birt:org.eclipse.birt.report.viewer: Improper Input Validation In Eclipse BIRTCVE-2023-24279Mediumorg.onosproject:onos-archetypes: ONOS vulnerable to reflected cross-site scriptingCVE-2023-28465Highca.uhn.hapi.fhir:org.hl7.fhir.core: HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057CVE-2023-27899Highorg.jenkins-ci.main:jenkins-core: Incorrect Authorization in Jenkins CoreCVE-2023-27901Highorg.jenkins-ci.main:jenkins-core: Denial of service in Jenkins CoreCVE-2023-27900Mediumorg.jenkins-ci.main:jenkins-core: Denial of service in Jenkins CoreCVE-2023-27898Highorg.jenkins-ci.main:jenkins-core: Cross-site Scripting vulnerability in JenkinsCVE-2023-27903Loworg.jenkins-ci.main:jenkins-core: Incorrect Authorization in Jenkins CoreCVE-2023-27905Mediumorg.jenkins-ci:update-center2: Cross site scripting vulnerability in update-center2 CVE-2023-27904Loworg.jenkins-ci.main:jenkins-core: Information disclosure through error stack traces related to agents CVE-2023-27902Mediumorg.jenkins-ci.main:jenkins-core: Incorrect Permission Preservation in Jenkins CoreCVE-2023-26464Highorg.apache.logging.log4j:log4j-core: Apache Log4j 1.x (EOL) allows Denial of Service (DoS)CVE-2023-27480Highorg.xwiki.platform:xwiki-platform-xar-model: XWiki Platform vulnerable to data leak via Improper Restriction of XML External Entity ReferenceCVE-2023-27479Criticalorg.xwiki.platform:xwiki-platform-panels-ui: org.xwiki.platform:xwiki-platform-panels-ui vulnerable to Eval InjectionCVE-2023-23638Criticalorg.apache.dubbo:dubbo: Apache Dubbo vulnerable to Deserialization of Untrusted DataCVE-2022-41918Mediumorg.opensearch.plugin:opensearch-security: OpenSearch has issue with fine-grained access control of indices backing data streamsCVE-2023-25806Mediumorg.opensearch.plugin:opensearch-security: OpenSearch has time discrepancy in authentication responsesCVE-2023-24789Highorg.jeecgframework.boot:jeecg-boot-parent: jeecg-boot contains SQL Injection vulnerabilityCVE-2023-26056Mediumorg.xwiki.platform:xwiki-platform-rendering-macro-context: xwiki contains Incorrect AuthorizationCVE-2023-26480Highorg.xwiki.platform:xwiki-platform-livedata-macro: XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live DataCVE-2023-26479Mediumorg.xwiki.platform:xwiki-platform-rendering-parser: xwiki vulnerable to Improper Handling of Exceptional ConditionsCVE-2023-26478Mediumorg.xwiki.platform:xwiki-platform-store-filesystem-oldcore: xwiki contains Exposed Dangerous Method or Function

Stop the waste.
Protect your environment with Kodem.