Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-19040Mediumorg.kairosdb:kairosdb: Reflected Cross site scripting (XSS) in kairosdbCVE-2022-43670Mediumorg.apache.sling:org.apache.sling.cms: Apache Sling App CMS vulnerable to Cross-site ScriptingCVE-2022-34662Mediumorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler vulnerable to Path TraversalCVE-2022-31777Mediumpyspark: Apache Spark vulnerable to Log InjectionCVE-2022-31690Highorg.springframework.security:spring-security-oauth2-client: spring-security-oauth2-client vulnerable to Privilege EscalationCVE-2022-31692Criticalorg.springframework.security:spring-security-core: Spring Security authorization rules can be bypassed via forward or include dispatcher typesCVE-2022-42252Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat may reject request containing invalid Content-Length headerCVE-2022-26884Mediumorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler vulnerable to Path TraversalCVE-2022-43766Highorg.apache.iotdb:flink-tsfile-connector: Apache IoTDB subject to ReDOS with Java 8CVE-2022-42468Criticalorg.apache.flume.flume-ng-sources:flume-jms-source: Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURLCVE-2022-39944Highorg.apache.linkis:linkis: Apache Linkis subject to Remote Code Execution via deserializationCVE-2022-41704Highorg.apache.xmlgraphics:batik: Apache XML Graphics Batik vulnerable to code execution via SVG.CVE-2022-42890Highorg.apache.xmlgraphics:batik: Untrusted code execution in Apache XML Graphics BatikCVE-2022-34870Mediumorg.apache.geode:geode-core: Apache Geode vulnerable to Cross-Site ScriptingCVE-2021-42010Criticalorg.apache.heron:heron-api: Heron allows CRLF log injectionCVE-2022-40084Mediumorg.opencrx:opencrx-client: OpenCRX vulnerable to password enumeration via error messages in password resetCVE-2022-39259Mediumio.github.skylot:jadx-plugins-api: Jadx-gui vulnerable to swing HTML Denial of Service (DoS) attackCVE-2022-31684Mediumio.projectreactor.netty:reactor-netty-http: Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokensCVE-2022-43412Loworg.jenkins-ci.plugins:generic-webhook-trigger: Non-constant time webhook token comparison in Jenkins Generic Webhook Trigger PluginCVE-2022-43407Highorg.jenkins-ci.plugins:pipeline-input-step: CSRF protection for any URL can be bypassed in Jenkins Pipeline: Input Step PluginCVE-2022-43433Highio.jenkins.plugins:screenrecorder: Content-Security-Policy protection for user content disabled by Jenkins ScreenRecorder PluginCVE-2022-43414Mediumorg.jenkins-ci.plugins:nunit: Jenkins NUnit Plugin vulnerable to Protection Mechanism FailureCVE-2022-43432Highorg.jenkins-ci.plugins:xframium: Content-Security-Policy protection for user content disabled by Jenkins XFramium Builder PluginCVE-2022-43413Mediumorg.jenkins-ci.plugins:job-import-plugin: Jenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in JenkinsCVE-2022-43421Mediumorg.jenkins-ci.plugins:tuleap-git-branch-source: Jenkins Tuleap Git Branch Source Plugin allows unauthenticated attackers to trigger Tuleap projects whose configured repo matches…

Stop the waste.
Protect your environment with Kodem.