Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-22096Mediumorg.springframework:spring-core: Improper Output Neutralization for Logs in Spring FrameworkCVE-2021-22044Highorg.springframework.cloud:spring-cloud-openfeign-core: Exposure of Resource to Wrong Sphere in Spring Cloud OpenFeignCVE-2021-22097Mediumorg.springframework.amqp:spring-amqp: Deserialization of Untrusted Data in Spring AMQPCVE-2021-22047Mediumorg.springframework.data:spring-data-rest-core: Exposure of Resource to Wrong Sphere in Spring Data RESTCVE-2021-2471Mediummysql:mysql-connector-java: Incorrect Authorization in MySQL Connector JavaCVE-2021-3869Highedu.stanford.nlp:stanford-corenlp: Improper Restriction of XML External Entity Reference in Stanford CoreNLPCVE-2021-3878Criticaledu.stanford.nlp:stanford-corenlp: Improper Restriction of XML External Entity Reference in Stanford CoreNLPCVE-2021-21682Mediumorg.jenkins-ci.main:jenkins-core: Improper handling of equivalent directory names on Windows in JenkinsCVE-2021-21683Mediumorg.jenkins-ci.main:jenkins-core: Path traversal vulnerability on Windows in JenkinsCVE-2021-21684Mediumorg.jenkins-ci.plugins:git: Stored XSS vulnerability in Jenkins Git PluginCVE-2021-40824Mediumorg.matrix.android:matrix-android-sdk2: Logic error in Matrix SDK for AndroidCVE-2021-21678Highorg.jenkins-ci.plugins:saml: Jenkins SAML Plugin allows bypassing CSRF protection for any URLCVE-2021-21677Highio.jenkins.plugins:code-coverage-api: RCE vulnerability in Jenkins Code Coverage API PluginCVE-2021-21681Mediumorg.jenkins-ci.plugins:nomad: Password stored in plain text by Jenkins Nomad PluginCVE-2021-21679Highorg.jenkins-ci.plugins:azure-ad: Jenkins Azure AD Plugin allows bypassing CSRF protection for any URLCVE-2021-21680Highorg.jenkins-ci.plugins:nested-view: XXE vulnerability in Jenkins Nested View PluginCVE-2021-28490Highorg.owasp:csrfguard: Cross-Site Request Forgery in OWASP CSRFGuardCVE-2020-28088Criticalorg.jeecgframework.boot:jeecg-boot-parent: Jeecg-Boot CMS arbitrary file upload vulnerabilityCVE-2021-3642Mediumorg.wildfly.security:wildfly-elytron: Observable Discrepancy in Wildfly ElytronCVE-2021-33335Highcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to TakeoversCVE-2021-33336Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)CVE-2021-33339Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site ScriptingCVE-2021-33338Highcom.liferay.portal:release.portal.bom: Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLsCVE-2021-33337Mediumcom.liferay:com.liferay.document.library.web: Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library moduleCVE-2021-35463Mediumcom.liferay.portal:release.portal.bom: Liferay Portal cross-site scripting (XSS) vulnerability in the Frontend Taglib module

Stop the waste.
Protect your environment with Kodem.