Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-15011Criticalbe.e_contract.dssp:dssp-client: dssp vulnerable to Improper Restriction of XML External Entity ReferenceCVE-2022-45787Mediumorg.apache.james:apache-mime4j-storage: Apache James MIME4J vulnerable to information disclosure to local usersCVE-2021-32828Mediumorg.nuxeo.ecm.platform:nuxeo-platform-oauth: Nuxeo vulnerable to Reflected Cross-Site Scripting leading to Remote Code ExecutionCVE-2020-36640Criticalorg.bonitasoft.connectors:bonita-connector-webservice: bonita-connector-webservice XML External Entity vulnerabilityCVE-2020-36641Criticalfr.turri:aXMLRPC: aXMLRPC XML External Entity vulnerabilityCVE-2022-45875Criticalorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler vulnerable to Improper Input ValidationCVE-2022-38723Highio.gravitee.apim:gravitee-api-management: Gravitee API Management contains Path TraversalCVE-2022-45143Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat improperly escapes input from JsonErrorReportValveCVE-2021-32824Criticalorg.apache.dubbo:dubbo-parent: Apache Dubbo vulnerable to remote code execution via Telnet HandlerCVE-2022-47551Highio.apiman:apiman-manager-api-rest-impl: Apiman has potential permissions bypassGHSA-Q2FJ-6H62-59M2Highio.apiman:apiman-gateway-platforms-vertx: Apiman Vert.x Gateway has Transitive Hazelcast connection caching issueCVE-2022-46178Highio.metersphere:metersphere: Path Traversal In MeterSpere leads to upload file to any pathCVE-2022-40151Highcom.thoughtworks.xstream:xstream: XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflowCVE-2022-44621Criticalorg.apache.kylin:kylin-server-base: Apache Kylin vulnerable to Command injection by Diagnosis ControllerCVE-2017-20151Criticalcom.itextpdf:itext-rups: iText RUPS XML External Entity vulnerabilityCVE-2022-43396Highorg.apache.kylin:kylin: Apache Kylin vulnerable to Command injection by Useless configurationCVE-2022-41966Highcom.thoughtworks.xstream:xstream: XStream can cause Denial of Service via stack overflowCVE-2022-4772Highcom.github.dgarijo:Widoco: Widoco Path Traversal vulnerabilityCVE-2022-4725Criticalcom.amazonaws:aws-android-sdk-mobile-client: AWS SDK is vulnerable to server-side request forgery (SSRF) CVE-2022-36437Criticalcom.hazelcast:hazelcast: Hazelcast connection cachingCVE-2022-45347Criticalorg.apache.shardingsphere:shardingsphere-proxy: Apache ShardingSphere-Proxy Incomplete Cleanup vulnerabilityCVE-2022-4640Mediumnet.mingsoft:ms-mcms: Mingsoft MCMS Cross-site Scripting vulnerabilityCVE-2022-40145Criticalorg.apache.karaf:apache-karaf: Apache Karaf vulnerable to potential code injectionCVE-2022-46870Mediumorg.apache.zeppelin:zeppelin: Apache Zeppelin Cross-site Scripting vulnerabilityCVE-2022-25940Highlite-server: lite-server vulnerable to Denial of Service

Stop the waste.
Protect your environment with Kodem.