Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-22832Highorg.apache.nifi:nifi-ccda-processors: XML External Entity Reference in Apache NiFiCVE-2023-24815Mediumio.vertx:vertx-web: StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard routeCVE-2023-25194Highorg.apache.kafka:connect: Apache Kafka Connect vulnerable to Deserialization of Untrusted DataCVE-2023-22849Mediumorg.apache.sling:org.apache.sling.cms: Sling App CMS Cross-site Scripting vulnerabilityCVE-2023-0674Mediumcom.xuxueli:xxl-job: Cross-Site Request Forgery in XXL JobCVE-2021-37305Highorg.jeecgframework.boot:jeecg-boot-base: Insecure Permissions issue in jeecg-bootCVE-2021-37306Highorg.jeecgframework.boot:jeecg-boot-base: Insecure Permissions issue in jeecg-bootCVE-2021-37304Highorg.jeecgframework.boot:jeecg-boot-base: Insecure Permissions issue in jeecg-bootCVE-2023-24997Criticalorg.apache.inlong:inlong: Apache InLong vulnerable to Deserialization of Untrusted Data vulnerabilityCVE-2023-24977Highorg.apache.inlong:inlong: Apache InLong contains Out-of-bounds Read vulnerabilityCVE-2023-24162Criticalcn.hutool:hutool-all: Dromara Hutool Deserialization of Untrusted Data vulnerabilityCVE-2023-24163Criticalcn.hutool:hutool-all: Dromara hutool vulnerable to SQL InjectionCVE-2022-44644Mediumorg.apache.linkis:linkis: Apache Linkis vulnerable to Exposure of Sensitive InformationCVE-2022-44645Highorg.apache.linkis:linkis: Apache Linkis contains Deserialization of Untrusted DataCVE-2022-25881Highhttp-cache-semantics: http-cache-semantics vulnerable to Regular Expression Denial of ServiceCVE-2022-2712Mediumorg.glassfish.main.web:web: Path Traversal In Eclipse GlassFishCVE-2022-25894Criticalcom.bstek.uflo:uflo-core: Remote Code Execution in com.bstek.uflo:uflo-coreCVE-2022-47042Highnet.mingsoft:ms-mcms: Arbitrary file write in net.mingsoft:ms-mcmsCVE-2023-24422Highorg.jenkins-ci.plugins:script-security: Sandbox bypass in Jenkins Script Security PluginCVE-2023-24439Mediumorg.jenkins-ci.plugins:jira-steps: Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps PluginCVE-2023-24441Criticalorg.jvnet.hudson.plugins:mstest: XML external entity vulnerability on agents in Jenkins MSTest Plugin CVE-2023-24426Highorg.jenkins-ci.plugins:azure-ad: Insufficient Session Expiration in Jenkins Azure AD PluginCVE-2023-24438Mediumorg.jenkins-ci.plugins:jira-steps: Missing permissions check in Jenkins JIRA Pipeline Steps PluginCVE-2023-24427Criticalorg.jenkins-ci.plugins:bitbucket-oauth: Session fixation vulnerability in Jenkins Bitbucket OAuth Plugin CVE-2023-24431Mediumio.jenkins.plugins:macstadium-orka: Missing permission checks in Jenkins Orka Plugin allow enumerating credentials IDs

Stop the waste.
Protect your environment with Kodem.