Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-34112Mediumio.dataease:dataease-plugin-common: Dataease before 1.11.2 access control issue allows attackers to arbitrarily uninstall pluginCVE-2022-34114Highio.dataease:dataease-plugin-common: SQL Injection found in Dataease CVE-2022-32430Highio.github.talelin:lin-cms-core: Hardcoded JWT Token in Lin CMS Spring BootGHSA-FJH6-P566-WR6QMediumio.github.skylot:jadx-core: skylot jadx affected by Incorrect Behavior Order in vulnerable dependencyCVE-2022-35912Criticalorg.grails:grails-databinding: Grails framework Remote Code Execution via Data BindingCVE-2016-1000273Criticalnet.bull.javamelody:javamelody-core: Java Melody vulnerable to cross-site scriptingCVE-2022-34169Highxalan:xalan: Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheetsCVE-2022-33891Highorg.apache.spark:spark-parent_2.12: Apache Spark UI can allow impersonation if ACLs enabledCVE-2020-7677Criticalthenify: thenify before 3.3.1 made use of unsafe calls to `eval`.CVE-2022-31160Mediumjquery-ui: jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text labelCVE-2021-34538Highorg.apache.hive:hive: Apache Hive before 3.1.3 `CREATE` and `DROP` function operations do not check for necessary authorization.CVE-2021-3859Highio.undertow:undertow-core: Undertow vulnerable to Denial of Service (DoS) attacksCVE-2021-3690Highio.undertow:undertow-core: Undertow vulnerable to memory exhaustion due to buffer leakCVE-2020-28191Highorg.togglz:togglz-console: Togglz console missing cross-site request forgery (CSRF) protectionCVE-2022-31159Highcom.amazonaws:aws-java-sdk-s3: Partial Path Traversal in com.amazonaws:aws-java-sdk-s3 CVE-2020-10650Highcom.fasterxml.jackson.core:jackson-databind: jackson-databind vulnerable to unsafe deserializationCVE-2015-8031Criticalorg.jvnet.hudson.main:hudson-core: Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2CVE-2021-4178Mediumio.fabric8:kubernetes-client: fabric8 kubernetes-client vulnerable CVE-2022-31781Highorg.apache.tapestry:tapestry-core: Apache Tapestry 5.8.1 vulnerable to ReDoS via Content Types causing catastrophic backtrackingCVE-2022-32065Mediumcom.ruoyi:ruoyi: RuoYi 4.7.3 vulnerable to arbitrary file upload in background management moduleCVE-2022-30187MediumAzure.Storage.Queues: Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption LibraryCVE-2022-31139Mediumio.github.karlatemp:unsafe-accessor: UnsafeAccessor 1.4.0 until 1.7.0 has no security checking for UnsafeAccess.getInstance()CVE-2022-27772Highorg.springframework.boot:spring-boot: Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-bootCVE-2021-44791Mediumorg.apache.druid:druid: Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parametersCVE-2022-28889Mediumorg.apache.druid:druid: Apache Druid before 0.23.0 vulnerable to clickjacking

Stop the waste.
Protect your environment with Kodem.