Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-37023Mediumorg.apache.geode:geode-core: Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted dataCVE-2022-37021Criticalorg.apache.geode:geode-core: Apache Geode vulnerable to Deserialization of Untrusted DataCVE-2022-2466Criticalio.quarkus:quarkus-core-parent: Quarkus does not terminate HTTP requests header contextCVE-2022-25857Highorg.yaml:snakeyaml: Uncontrolled Resource Consumption in snakeyamlCVE-2021-3856Mediumorg.keycloak:keycloak-core: Keycloak has Files or Directories Accessible to External PartiesCVE-2021-3644Loworg.wildfly.core:wildfly-server: wildfly-core allows user with access to management interface to access vault expression, retrieve item from vaultCVE-2021-3632Highorg.keycloak:keycloak-core: Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flowCVE-2022-0084Highorg.jboss.xnio:xnio-all: XNIO `notifyReadClosed` method logging message to unexpected endCVE-2022-0225Mediumorg.keycloak:keycloak-core: Keycloak XSS via use of malicious payload as group name when creating new group from admin consoleCVE-2022-36537Highorg.zkoss.zk:zk: ZK Framework vulnerable to malicious POSTCVE-2021-25642Highorg.apache.hadoop:hadoop-yarn-server: Deserialization of Untrusted Data in Apache Hadoop YARNCVE-2022-36527Mediumcom.jflyfox:jflyfox_jfinal: Jfinal Cross-site Scripting vulnerabilityCVE-2021-3914Mediumio.smallrye:smallrye-health-ui: SmallRye Health UI Cross-site Scripting vulnerabilityCVE-2021-4040Mediumorg.apache.activemq:artemis-core-client: org.apache.activemq:artemis-core-client Vulnerable to Out-of-Bounds WriteCVE-2019-25075Mediumio.gravitee.apim:gravitee-api-management: Path Traversal in Gravitee API Management CVE-2022-37223Criticalcom.jflyfox:jflyfox_jfinal: SQL injection in jflyfox jfinalCVE-2020-35509Mediumorg.keycloak:keycloak-core: Keycloak vulnerable to Improper Certificate ValidationCVE-2022-37199Criticalcom.jflyfox:jflyfox_jfinal: SQL injection in jflyfox jfinalCVE-2022-35278Mediumorg.apache.activemq:artemis-server: HTML Injection in ActiveMQ Artemis Web ConsoleCVE-2022-38663Mediumorg.jenkins-ci.plugins:git: Improper masking of credentials Jenkins in Git PluginCVE-2022-38664Mediumorg.jenkins-ci.plugins:jobConfigHistory: Cross-site Scripting in Jenkins Job Configuration History PluginCVE-2022-38665Loworg.jenkins-ci.plugins:collabnet: RabbitMQ password stored in plain text by Jenkins CollabNet Plugins PluginCVE-2021-3513Highorg.keycloak:keycloak-parent: Incorrect implementation of lockout feature in KeycloakCVE-2022-34916Criticalorg.apache.flume.flume-ng-sources:flume-jms-source: Remote code execution in Apache FlumeCVE-2022-36157Highcom.xuxueli:xxl-job: Improper Privilege Management in com.xuxueli:xxl-job

Stop the waste.
Protect your environment with Kodem.