Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2012-6612Highorg.apache.solr:solr-core: Improper Restriction of XML External Entity Reference in Apache SolrCVE-2013-1777Highorg.apache.geronimo.framework:geronimo-jmx-remoting: Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1CVE-2014-1216Highorg.fitnesse:fitnesse: Improper Neutralization of Special Elements used in a Command in FitNesse WikiCVE-2013-4310Mediumorg.apache.struts:struts2-core: Apache Struts2 Broken Access Control VulnerabilityCVE-2014-2741Highorg.igniterealtime.openfire:parent: Ignite Realtime Openfire vulnerable to XMPPbomb attackCVE-2013-6372Mediumorg.jenkins-ci.plugins:subversion: Jenkins Subversion Plugin Stores Credentials with Base64 EncodingCVE-2013-6408Mediumorg.apache.solr:solr-core: XML Injection in Apache SolrCVE-2013-6407Mediumorg.apache.solr:solr-core: Apache Solr UpdateRequestHandler for XML resolves XML External EntitiesCVE-2013-7259Highorg.neo4j:neo4j: Neo4J vulnerable to Cross-Site Request ForgeryCVE-2014-0168Mediumorg.jolokia:jolokia-core: Cross-Site Request Forgery in JolokiaCVE-2014-5326Mediumorg.directwebremoting:dwr: Improper Neutralization of Input During Web Page Generation in Direct Web RemotingCVE-2014-3627Mediumorg.apache.hadoop:hadoop-client: Improper Link Resolution Before File Access in Apache HadoopCVE-2014-3628Mediumorg.apache.solr:solr: Improper Neutralization of Input During Web Page Generation in Apache SolrCVE-2013-2035Mediumorg.fusesource.hawtjni:hawtjni-runtime: Improper Control of Generation of Code in HawtJNICVE-2012-5370Mediumorg.jruby:jruby-parent: JRuby denial of service via Hash CollisionCVE-2014-7816Mediumio.undertow:undertow-core: Improper Limitation of a Pathname to a Restricted Directory in JBoss UndertowCVE-2014-7839Mediumorg.jboss.resteasy:resteasy-jaxrs: XML External Entity Reference in RESTEasyCVE-2014-8125Highorg.drools:drools-core: Improper Input Validation in Drools and jBPMCVE-2015-3337Mediumorg.elasticsearch:elasticsearch: Improper Limitation of a Pathname to a Restricted Directory in ElasticsearchCVE-2015-3158Mediumorg.picketlink:picketlink-tomcat-common: PicketLink does not properly check role based authorizationCVE-2013-6397Mediumorg.apache.solr:solr-core: Improper Limitation of a Pathname to a Restricted Directory in Apache SolrCVE-2015-5210Mediumorg.apache.ambari:ambari: Apache Ambari Open RedirectCVE-2015-1775Mediumorg.apache.ambari:ambari: Apache Ambari SSRF VulnerabilityCVE-2015-8795Mediumorg.apache.solr:solr-core: Improper Neutralization of Input During Web Page Generation in Apache SolrCVE-2015-8797Mediumorg.apache.solr:solr-core: Improper Neutralization of Input During Web Page Generation in Apache Solr

Stop the waste.
Protect your environment with Kodem.