Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-34174Mediumorg.jenkins-ci.main:jenkins-core: Observable timing discrepancy allows determining username validity in JenkinsCVE-2022-33113Mediumcom.jfinal:jfinal: Cross-site Scripting in Jfinal CMSCVE-2022-22980Criticalorg.springframework.data:spring-data-mongodb: SpEL Injection in Spring Data MongoDBCVE-2022-32549Mediumorg.apache.sling:org.apache.sling.commons.log: Log Injection in Apache Sling Commons Log and Apache Sling APICVE-2022-22979Highorg.springframework.cloud:spring-cloud-function-parent: Denial of Service in Spring Cloud FunctionCVE-2022-26850Mediumorg.apache.nifi:nifi-single-user-utils: Insufficiently Protected Credentials via Insecure Temporary File in org.apache.nifi:nifi-single-user-utilsCVE-2022-31044Highorg.rundeck:rundeck: Rundeck's Key Storage converter plugin mechanism's encryption layer not working in 4.2.0, 4.2.1, 4.3.0CVE-2022-31053Criticalbiscuit-auth: Signature forgery in BiscuitCVE-2021-41411Criticalorg.drools:drools-core: XML External Entity Reference in droolsCVE-2020-28865Highcom.github.kfcfans:powerjob: Insufficiently Protected Credentials in PowerJobCVE-2022-33140Highorg.apache.nifi.registry:nifi-registry-core: Code injection in Apache NiFi and NiFi RegistryCVE-2021-33036Highorg.apache.hadoop:hadoop-yarn-server-common: User account escalation in Apache HadoopCVE-2022-25167Highorg.apache.flume.flume-ng-sources:flume-jms-source: Remote Code Execution in Apache FlumeCVE-2021-40660Highorg.javadelight:delight-nashorn-sandbox: Regular expression denial of service in Delight Nashorn SandboxCVE-2021-37404Criticalorg.apache.hadoop:hadoop-common: Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2CVE-2022-25845Highcom.alibaba:fastjson: Unsafe deserialization in com.alibaba:fastjsonCVE-2022-24969Mediumorg.apache.dubbo:dubbo: Server-side request forgery in Apache DubboCVE-2022-23712Highorg.elasticsearch:elasticsearch: Improper Check for Unusual or Exceptional Conditions in ElasticsearchCVE-2022-29631Highorg.jodd:jodd-http: Server-Side Request Forgery in Jodd HTTPCVE-2022-29770Mediumcom.xuxueli:xxl-job: Cross site scripting in XXL-jobCVE-2022-31023Mediumcom.typesafe.play:play_2.12: Dev error stack trace leaking into prod in Play FrameworkCVE-2022-31018Highcom.typesafe.play:play_2.13: Denial of service binding form from JSON in Play FrameworkCVE-2022-30506Criticalnet.mingsoft:ms-mcms: Code injection in MCMSCVE-2022-29647Highnet.mingsoft:ms-mcms: Cross Site Request Forgery in Mingsoft MCMSCVE-2022-29648Mediumcom.jflyfox:jflyfox_jfinal: Cross site scripting in Jfinal

Stop the waste.
Protect your environment with Kodem.