Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-28732Mediumorg.apache.jspwiki:jspwiki-main: Apache JSPWiki XSS due to crafted request in WeblogPluginCVE-2022-25168Criticalorg.apache.hadoop:hadoop-common: Apache Hadoop argument injection vulnerabilityCVE-2022-25867Highio.socket:socket.io-client: Socket.IO-client Java before 2.0.1 vulnerable to NULL Pointer DereferenceCVE-2022-2576Highorg.eclipse.californium:californium-core: Eclipse Californium denial of service (DoS) via Datagram Transport Layer Security (DTLS) handshake on parameter mismatchCVE-2022-31183Criticalco.fs2:fs2-io: fs2-io skips mTLS client verificationCVE-2022-36364Highorg.apache.calcite.avatica:avatica-core: Apache Calcite Avatica JDBC driver arbitrary code executionCVE-2022-36884Mediumorg.jenkins-ci.plugins:git: Lack of authentication mechanism in Jenkins Git Plugin webhookCVE-2022-36883Mediumorg.jenkins-ci.plugins:git: Lack of authentication mechanism in Jenkins Git Plugin webhookCVE-2022-36882Mediumorg.jenkins-ci.plugins:git: Lack of authentication mechanism in Jenkins Git Plugin webhookCVE-2022-36881Mediumorg.jenkins-ci.plugins:git-client: Jenkins Git client plugin 3.11.0 does not perform SSH host key verificationCVE-2022-36887Mediumorg.jenkins-ci.plugins:jobConfigHistory: Jenkins Job Configuration History Plugin does not require POST requests for several HTTP endpointsCVE-2022-36888Mediumcom.datapipe.jenkins.plugins:hashicorp-vault-plugin: Jenkins HashiCorp Vault Plugin does not perform permission checks in several HTTP endpoints that perform Vault connection testsCVE-2022-36886Mediumorg.jenkins-ci.plugins:external-monitor-job: External Monitor Job Type Plugin does not require POST requests for an HTTP endpointCVE-2022-36885Lowcom.coravy.hudson.plugins.github:github: Jenkins GitHub plugin uses weak webhook signature functionCVE-2022-36893Mediumorg.jenkins-ci.plugins:rpmsign-plugin: Jenkins rpmsign-plugin does not perform a permission check in a method implementing form validationCVE-2022-36891Mediumorg.jenkins-ci.plugins:deployer-framework: Jenkins Deployer Framework Plugin allows attackers with Item/Read permission to read deployment logsCVE-2022-36889Mediumorg.jenkins-ci.plugins:deployer-framework: Jenkins Deployer Framework Plugin does not restrict application path of applications when configuring a deploymentCVE-2022-36890Mediumorg.jenkins-ci.plugins:deployer-framework: Jenkins Deployer Framework Plugin vulnerable to Path TraversalCVE-2022-36899Mediumcom.compuware.jenkins:compuware-ispw-operations: Agent-to-controller security bypass in Jenkins BMC Compuware ISPW Operations pluginCVE-2022-36895Mediumcom.compuware.jenkins:compuware-topaz-utilities: Jenkins Compuware Topaz Utilities Plugin is missing authorizationCVE-2022-36892Mediumorg.jenkins-ci.plugins:rhnpush-plugin: Jenkins rhnpush-plugin does not perform a permission check in a method implementing form validationCVE-2022-36902Highcom.moded.extendedchoiceparameter:dynamic_extended_choice_parameter: Stored XSS vulnerability in Jenkins Dynamic Extended Choice Parameter pluginCVE-2022-36898Mediumcom.compuware.jenkins:compuware-ispw-operations: Jenkins Compuware ISPW Operations Plugin does not perform permission checks in several HTTP endpointsCVE-2022-36903Mediumorg.jenkins-ci.plugins:repository-connector: Jenkins Repository Connector Plugin allows attackers with Overall/Read permission to enumerate credentials IDsCVE-2022-36897Mediumcom.compuware.jenkins:compuware-xpediter-code-coverage: Jenkins Compuware Xpediter Code Coverage Plugin Missing Authorization

Stop the waste.
Protect your environment with Kodem.