Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-37422Highfish.payara.api:payara-bom: Path Traversal in PayaraCVE-2022-36007Mediumcom.github.jlangch:venice: Venice vulnerable to Partial Path Traversal issue within the functions `load-file` and `load-resource`CVE-2022-38216Highcom.mapbox.mapboxsdk:mapbox-android-core: Mapbox is vulnerable to Integer OverflowCVE-2022-36599Criticalnet.mingsoft:ms-mcms: Mingsoft MCMS SQL injection vulnerability in /mdiy/model/delete URI via models ListCVE-2022-36272Criticalnet.mingsoft:ms-mcms: Mingsoft MCMS SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameterCVE-2020-23622Highorg.fourthline.cling:cling-core: 4thline cling uPnP protocol issue can lead to denial of serviceCVE-2022-38180Mediumio.ktor:ktor: JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication providerCVE-2022-38179Mediumio.ktor:ktor: JetBrains Ktor before 2.1.0 was vulnerable to a Reflect File Download attackCVE-2022-2390Mediumcom.google.android.gms:play-services-basement: Google Play Services SDK leads to apps having incorrectly set mutability flagCVE-2022-35980Highorg.opensearch.plugin:opensearch-security: OpenSearch vulnerable to Improper Authorization of Index Containing Sensitive InformationCVE-2022-37423Mediumorg.neo4j.procedure:apoc: Neo4j Graph apoc plugins Partial Path Traversal VulnerabilityCVE-2022-35697Mediumcom.adobe.cq:core.wcm.components.core: AEM WCM Core Components CVG Image vulnerable to Reflected Cross-site ScriptingCVE-2022-31197Highorg.postgresql:postgresql: PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column namesCVE-2022-31195Highorg.dspace:dspace-api: DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package ImportCVE-2022-31194Highorg.dspace:dspace-jspui: JSPUI vulnerable to path traversal in submission (resumable) uploadCVE-2022-31193Highorg.dspace:dspace-jspui: JSPUI's controlled vocabulary feature vulnerable to Open Redirect before v6.4 and v5.11CVE-2022-31192Highorg.dspace:dspace-jspui: JSPUI Possible Cross Site Scripting in "Request a Copy" FeatureCVE-2022-31191Highorg.dspace:dspace-jspui: JSPUI spellcheck and autocomplete tools vulnerable to Cross Site ScriptingCVE-2022-31190Mediumorg.dspace:dspace-xmlui: XMLUI's metadata of withdrawn Items is exposed to anonymous usersCVE-2022-31189Mediumorg.dspace:dspace-jspui: JSPUI's "Internal System Error" page prints exceptions and stack traces without sanitizationCVE-2022-2053Highio.undertow:undertow-core: Undertow vulnerable to Dos via Large AJP requestCVE-2022-27166Mediumorg.apache.jspwiki:jspwiki-main: Apache JSPWiki XSS due to crafted request on XHRHtml2Markup.jspCVE-2022-34158Highorg.apache.jspwiki:jspwiki-main: Apache JSPWiki CSRF due to crafted invocation on the Image pluginCVE-2022-28731Mediumorg.apache.jspwiki:jspwiki-main: Apache JSPWiki CSRF due to crafted request on UserPreferences.jspCVE-2022-28730Mediumorg.apache.jspwiki:jspwiki-main: Apache JSPWiki XSS due to incomplete patch for CVE-2021-40369

Stop the waste.
Protect your environment with Kodem.