Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-30948Loworg.jenkins-ci.plugins:mercurial: Path traversal in Jenkins Mercurial PluginCVE-2022-30950Mediumorg.jenkins-ci.plugins:windows-slaves: Buffer overflow in Jenkins WMI Windows Agents pluginCVE-2022-30946Mediumorg.jenkins-ci.plugins:script-security: CSRF vulnerability in Jenkins Script Security PluginCVE-2022-30947Highorg.jenkins-ci.plugins:git: Path traversal in Jenkins Git Mercurial and Repo PluginsCVE-2022-30945Highorg.jenkins-ci.plugins.workflow:workflow-cps: Sandbox bypass vulnerability through implicitly allowlisted platform Groovy files in Jenkins Pipeline: Groovy PluginCVE-2014-9390Criticalorg.eclipse.jgit:org.eclipse.jgit: JGit Improper Input Validation vulnerabilityCVE-2014-4172CriticalDotNetCasClient: Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerabilityCVE-2014-3643Highcom.sun.jersey:jersey-core: jersey: XXE via parameter entitiesCVE-2014-3652Mediumorg.keycloak:keycloak-services: JBoss KeyCloak Open RedirectCVE-2014-3656Mediumorg.keycloak:keycloak-core: JBoss KeyCloak Cross-site Scripting VulnerabilityCVE-2014-3655Mediumorg.keycloak:keycloak-services: JBoss KeyCloak is vulnerable to soft token deletion via CSRFCVE-2008-6682Mediumorg.apache.struts:struts2-core: Apache Struts is vulnerable to Cross-site ScriptingCVE-2008-6505Mediumorg.apache.struts:struts2-core: Apache Struts directory traversal vulnerabilityCVE-2010-2086Mediumorg.apache.myfaces.core:myfaces-core-module: Apache MyFaces Cross-site Scripting vulnerabilityCVE-2010-2274Mediumorg.dojotoolkit:dojo: Dojo Open Redirect vulnerabilityCVE-2010-2057Mediumorg.apache.myfaces.shared:myfaces-shared-core: Improper Authentication in Apache MyFacesCVE-2010-3708Highorg.drools:drools-core: Drools Improper Input Validation vulnerability allows remote attackers to execute arbitrary code in JBoss EAPCVE-2011-2087Mediumorg.apache.struts:struts2-parent: Apache Struts Multiple XSS VulnerabilitiesCVE-2011-1498Mediumorg.apache.httpcomponents:httpclient: Exposure of Sensitive Information to an Unauthorized Actor in Apache HttpClientCVE-2011-4457Lowcom.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer: OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabledCVE-2011-4905Mediumorg.apache.activemq:activemq-core: Denial of Service in Apache ActiveMQCVE-2011-1772Loworg.apache.struts:struts2-core: Cross-site Scripting in Apache StrutsCVE-2011-3375Mediumorg.apache.tomcat:tomcat: Apache Tomcat Exposes IP Addresses and HTTP Headers of RequestsCVE-2012-2138Mediumorg.apache.sling:org.apache.sling.servlets.post: Apache Sling POST Servlets Denial of Service VulnerabilityCVE-2012-2967Highcom.caucho:resin: Caucho Quercus, as distributed in Resin, does not properly implement the `==` operator for comparisons

Stop the waste.
Protect your environment with Kodem.