Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-47500Mediumorg.apache.helix:helix: Apache Helix UI vulnerable to Open RedirectCVE-2022-4565Highcn.hutool:hutool-core: HuTool vulnerable to Uncontrolled Resource ConsumptionCVE-2022-32531Mediumorg.apache.bookkeeper:bookkeeper-common: Apache Bookkeeper vulnerable to Improper Certificate ValidationCVE-2022-4521Mediumorg.wso2.carbon.registry:carbon-registry: WSO2 carbon-registry vulnerable to Cross-site ScriptingCVE-2022-4520Mediumorg.wso2.carbon.registry:carbon-registry: WSO2 carbon-registry Cross-site Scripting vulnerabilityCVE-2022-4493Criticalio.scif:scifio: SCIFIO vulnerable to Path TraversalCVE-2022-34271Highorg.apache.atlas:apache-atlas: Apache Atlas: zip path traversal in import functionalityCVE-2022-3782Criticalorg.keycloak:keycloak-parent: Keycloak vulnerable to path traversal via double URL encoding CVE-2022-3916Mediumorg.keycloak:keycloak-parent: Keycloak vulnerable to session takeover with OIDC offline refreshtokensCVE-2022-46364Criticalorg.apache.cxf:cxf-core: Apache CXF Server-Side Request Forgery vulnerabilityCVE-2022-45693Highorg.codehaus.jettison:jettison: Jettison Out-of-bounds Write vulnerabilityCVE-2022-46363Highorg.apache.cxf:cxf-core: Apache CXF vulnerable to Exposure of Sensitive InformationCVE-2022-45688Highorg.json:json: json stack overflow vulnerabilityCVE-2022-45690Mediumcn.hutool:hutool-json: hutool-json stack overflow vulnerabilityCVE-2022-45685Highorg.codehaus.jettison:jettison: Jettison Out-of-bounds Write vulnerabilityCVE-2022-45689Lowcn.hutool:hutool-json: hutool-json vulnerable to memory exhaustionCVE-2022-41915Mediumio.netty:netty-codec-http: Netty vulnerable to HTTP Response splitting from assigning header value iteratorCVE-2022-41881Mediumio.netty:netty-codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoSCVE-2022-1471Highorg.yaml:snakeyaml: SnakeYaml Constructor Deserialization Remote Code ExecutionCVE-2022-3510Highcom.google.protobuf:protobuf-java: Protobuf Java vulnerable to Uncontrolled Resource ConsumptionCVE-2022-3509Highcom.google.protobuf:protobuf-java: Protobuf Java vulnerable to Uncontrolled Resource ConsumptionCVE-2022-46688Mediumorg.jenkins-ci.plugins:sonar-gerrit: Jenkins Sonar Gerrit Plugin vulnerable to Cross-Site Request ForgeryCVE-2022-46684Highcom.checkmarx.jenkins:checkmarx: Stored XSS vulnerability in Jenkins Checkmarx PluginCVE-2022-46683Mediumorg.jenkins-ci.plugins:google-login: Jenkins Google Login Plugin Open Redirect vulnerabilityCVE-2022-46682Highorg.jenkins-ci.plugins:plot: Jenkins Plot Plugin XML External Entity Reference vulnerability

Stop the waste.
Protect your environment with Kodem.