Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-46686Highio.jenkins.plugins:custom-build-properties: Jenkins Custom Build Properties Plugin vulnerable to Cross-site ScriptingCVE-2022-46685Mediumorg.jenkins-ci.plugins:gitea: Jenkins Gitea Plugin vulnerable to Cleartext Transmission of Sensitive InformationCVE-2022-46687Highio.jenkins.plugins:spring-config: Cross-site Scripting in Jenkins Spring Config PluginCVE-2022-46166Highde.codecentric:spring-boot-admin: Spring Boot Admins integrated notifier support allows arbitrary code executionCVE-2022-4375Criticalnet.mingsoft:ms-mcms: Mingsoft MCMS vulnerable to SQL InjectionCVE-2022-23496Highnl.basjes.parse.useragent:yauaa: Yauaa vulnerable to ArrayIndexOutOfBoundsException triggered by a crafted Sec-Ch-Ua-Full-Version-ListCVE-2022-4350Mediumnet.mingsoft:ms-mcms: Mingsoft MCMS vulnerable to Cross-site ScriptingCVE-2022-4348Mediumcom.ruoyi:ruoyi-common: RuoYi-Cloud Cross-site Scripting vulnerabilityCVE-2022-4147Highio.quarkus:quarkus-vertx-http: Quarkus CORS filter allows simple GET and POST requests with an invalid Origin to proceedCVE-2022-45046Criticalorg.apache.camel:camel-ldap: camel-ldap component allows LDAP Injection when using the filter optionCVE-2022-43484Highorg.terasoluna.gfw:terasoluna-gfw-common: TERASOLUNA Server Framework vulnerable to ClassLoader manipulationCVE-2021-37533Mediumcommons-net:commons-net: Apache Commons Net vulnerable to information leakage via malicious serverCVE-2022-46366Criticalorg.apache.tapestry:tapestry-core: Apache Tapestry allows deserialization of untrusted dataCVE-2022-44262Criticalorg.ff4j:ff4j-core: ff4j is vulnerable to Remote Code Execution (RCE)CVE-2022-41965Mediumorg.opencastproject:opencast-common: Authenticated OpenRedirect VulnerabilityGHSA-755V-R4X4-QF7MMediumorg.keycloak:keycloak-core: Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdownCVE-2022-21126Highcom.github.samtools:htsjdk: HTSJDK is vulnerable to exposure of resource(s) to the wrong sphereCVE-2022-41954Lownet.sf.mpxj:mpxj: Temporary File Information Disclosure vulnerability in MPXJCVE-2022-45921Highio.fusionauth:fusionauth-java-client: FusionAuth vulnerable to directory traversal attackCVE-2022-45206Criticalorg.jeecgframework.boot:jeecg-module-system: Jeecg-boot vulnerable to SQL InjectionCVE-2022-45208Mediumorg.jeecgframework.boot:jeecg-module-system: Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBinCVE-2022-45210Mediumorg.jeecgframework.boot:jeecg-module-system: Jeecg-boot vulnerable to SQL InjectionCVE-2022-45207Criticalorg.jeecgframework.boot:jeecg-module-system: Jeecg-boot vulnerable to SQL injection via updateNullByEmptyStringCVE-2022-26885Highorg.apache.dolphinscheduler:dolphinscheduler-common: Apache Dolphin Scheduler has insufficiently protected credentials CVE-2022-41946Mediumorg.postgresql:postgresql: TemporaryFolder on unix-like systems does not limit access to created files

Stop the waste.
Protect your environment with Kodem.