Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-22118Highorg.springframework:spring-web: Improper Privilege Management in Spring FrameworkCVE-2021-21659Highorg.jenkins-ci.plugins:urltrigger: XXE vulnerability in Jenkins URLTrigger PluginCVE-2021-21657Highorg.jenkins-ci.plugins:fstrigger: XXE vulnerability in Jenkins Filesystem Trigger PluginCVE-2021-21660Mediumio.jenkins.plugins:markdown-formatter: XSS vulnerability in Jenkins Markdown Formatter PluginCVE-2021-21658Criticalorg.jenkins-ci.plugins:nuget: XML external entity vulnerability in Jenkins Nuget PluginCVE-2021-23937Highorg.apache.wicket:wicket-core: DNS based denial of service in Apache WicketCVE-2021-25934Mediumorg.opennms:opennms: OpenNMS Horizon vulnerable to XSSCVE-2021-29053Highcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Multiple SQL InjectionsCVE-2021-29043Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy PasswordCVE-2021-29044Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin PageCVE-2021-29046Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module ParameterCVE-2021-29048Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in the Layout Admin PageCVE-2021-29045Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin PageCVE-2021-29052Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Fails to Check PermissionsCVE-2021-29051Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Asset Publisher AppCVE-2021-29039Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin PageCVE-2021-29041Mediumcom.liferay.portal:release.dxp.bom: Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication ModuleCVE-2021-29047Highcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After UseCVE-2021-29040Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Reveals Data via Overly Verbose Error MessagesCVE-2021-20250Mediumorg.jboss:jboss-ejb-client: JBoss EJB Client information disclosure vulnerabilityCVE-2021-22137Mediumorg.elasticsearch:elasticsearch: Exposure of Sensitive Information to an Unauthorized Actor in ElasticsearchCVE-2021-21647Mediumorg.jenkins-ci.plugins:electricflow: Missing permission check in Jenkins CloudBees CD Plugin allows scheduling buildsCVE-2021-21642Highorg.jenkins-ci.plugins:config-file-provider: XML External Entity Reference vulnerability in Jenkins Config File Provider PluginCVE-2021-21645Mediumorg.jenkins-ci.plugins:config-file-provider: Missing permission checks in Jenkins Config File Provider Plugin allow enumerating configuration file IDsCVE-2021-21646Highorg.jenkins-ci.plugins:templating-engine: Remote code execution vulnerability in Jenkins Templating Engine Plugin

Stop the waste.
Protect your environment with Kodem.