Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-39246Highorg.matrix.android:matrix-android-sdk2: matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessionsCVE-2022-39243Highcom.zaxxer:nuprocess: NuProcess vulnerable to command-line injection through insertion of NUL character(s)CVE-2021-43980Loworg.apache.tomcat:tomcat: Apache Tomcat Race Condition vulnerabilityCVE-2022-40929Criticalcom.xuxueli:xxl-job-core: XXL-JOB contains a Command execution vulnerability in background tasks CVE-2022-33683Mediumorg.apache.pulsar:pulsar-broker: Apache Pulsar Brokers and Proxies vulnerable to Improper Certificate ValidationCVE-2022-33681Mediumorg.apache.pulsar:pulsar-client: Apache Pulsar Java Client vulnerable to Improper Certificate ValidationCVE-2022-33682Mediumorg.apache.pulsar:pulsar-broker: Apache Pulsar Broker, Proxy, and WebSocket Proxy vulnerable to Improper Certificate ValidationCVE-2022-26112Criticalorg.apache.pinot:pinot: Apache Pinot has Groovy Function support enabled by defaultCVE-2022-36944Criticalorg.scala-lang:scala-library: Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserializationCVE-2022-24280Mediumorg.apache.pulsar:pulsar: Proxy component of Apache Pulsar subject to abuse as Denial of Service endpointCVE-2022-23463Criticalcom.nepxion:discovery: Nepxion Discovery vulnerable to SpEL Injection leading to Remote Code ExecutionCVE-2022-23464Mediumcom.nepxion:discovery: Nepxion Discovery vulnerable to potential Information Disclosure due to Server-Side Request Forgery CVE-2022-36025Criticalorg.hyperledger.besu:evm: Besu VM vulnerable to gas allocation error in CALL operationsCVE-2022-2256Mediumorg.keycloak:keycloak-parent: Keycloak vulnerable to Stored Cross site Scripting (XSS) when loading default rolesCVE-2022-2668Highorg.keycloak:keycloak-parent: Keycloak SAML javascript protocol mapper: Uploading of scripts through admin consoleCVE-2022-40705Highsoap:soap: Apache SOAP's RPCRouterServlet allows reading of arbitrary files over HTTPCVE-2022-28980Mediumcom.liferay:com.liferay.fragment.renderer.collection.filter.impl: Liferay Portal and Liferay DXP Vulnerable to XSS via the filter_ PrefixCVE-2022-39975Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Missing Authorization vulnerabilityCVE-2022-38512Mediumcom.liferay:com.liferay.translation.web: Liferay Portal and Liferay DXP Fails to Check Permissions in Translation ModuleCVE-2022-28978Mediumcom.liferay:com.liferay.site.memberships.web: Liferay Portal and Liferay DXP Vulnerable to XSS in the Site ModuleCVE-2022-28982Mediumcom.liferay:com.liferay.asset.taglib: Liferay Portal and Liferay DXP Vulnerable to XSS via Tag NameCVE-2022-28977Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP HtmlUtil.escapeRedirect Can Be CircumventedCVE-2022-28981Highcom.liferay:com.liferay.headless.discovery.web: Liferay Portal Path Traversal Vulnerability via the Hypermedia REST APIs ModuleCVE-2022-28979Mediumcom.liferay:com.liferay.portal.search.web: Liferay Portal and Liferay DXP Vulnerable to XSS in the Portal Search ModuleCVE-2022-40146Highorg.apache.xmlgraphics:batik: Apache Batik vulnerable to Server-Side Request Forgery

Stop the waste.
Protect your environment with Kodem.