Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-29258Highorg.xwiki.platform:xwiki-platform-filter-ui: Cross-site Scripting in Filter Stream Converter Application in XWiki PlatformCVE-2022-29253Loworg.xwiki.platform:xwiki-platform-oldcore: Path Traversal in XWiki PlatformCVE-2022-30973Mediumorg.apache.tika:tika-core: Regular expression denial of service in apache tikaCVE-2022-23082Highio.whitesource:curekit: Path traversal in CureKitCVE-2022-30500Highcom.jflyfox:jflyfox_jfinal: SQL injection in jflyfox jfinalCVE-2022-29405Mediumorg.apache.archiva:archiva: Missing Authorization in Apache ArchivaCVE-2022-29252Highorg.xwiki.platform:xwiki-platform-wiki-ui-mainwiki: Cross-site Scripting in wiki manager join wiki pageCVE-2022-29251Highorg.xwiki.platform:xwiki-platform-flamingo-theme-ui: Cross-site Scripting in the Flamingo theme managerCVE-2022-29567Mediumcom.vaadin:vaadin: Possible information disclosure inside TreeGrid component with default data providerCVE-2022-29249Highio.github.javaezlib:JavaEZ: Reversible One-Way Hash in io.github.javaezlib:JavaEZCVE-2022-29237Mediumorg.opencastproject:opencast-ingest-service-impl: Limited Authentication Bypass for Media FilesCVE-2019-17352Highcom.jfinal:jfinal: JFinal file validation vulnerabilityCVE-2022-1848Mediumcom.erudika:para-core: Business Logic Errors in ParaCVE-2021-3629Highio.undertow:undertow-core: Undertow Uncontrolled Resource ConsumptionCVE-2021-3717Highorg.wildfly.core:wildfly-core-parent: Wildfly-Core user account mismanagementCVE-2021-3597Mediumio.undertow:undertow-core: undertow Race Condition vulnerabilityCVE-2021-33322Highcom.liferay.portal:com.liferay.portal.impl: Liferay Portal and Liferay DXP fails to invalidate password reset tokens after useCVE-2021-20328Mediumorg.mongodb:mongodb-driver: Improper Certificate Validation in MongoDBCVE-2019-10169Highorg.keycloak:keycloak-authz-client: Keycloak code execution via UMA policy abuseCVE-2019-17560Criticalorg.codehaus.mevenide:netbeans: Improper Certificate Validation in Apache NetbeansCVE-2021-33330Mediumcom.liferay.portal:release.portal.bom: Exposure of Resource to Wrong Sphere in Liferay PortalCVE-2021-29049Mediumcom.liferay.portal:release.dxp.bom: Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL ParameterCVE-2021-21662Mediumcom.xebialabs.deployit.ci:deployit-plugin: Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows enumerating credentials IDsCVE-2020-1695Highorg.jboss.resteasy:resteasy-client: Improper Input Validation in RESTEasyCVE-2019-20366Mediumorg.igniterealtime.openfire:parent: XSS in Ignite Realtime Openfire via isTrustStore

Stop the waste.
Protect your environment with Kodem.