Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-3082Criticalorg.apache.struts:struts2-core: Remote Code Execution in Apache StrutsCVE-2016-3093Mediumorg.apache.struts:struts2-core: Denial of service in Apache StrutsCVE-2015-1796Mediumorg.opensaml:opensaml: Improper Certificate Validation in Shibboleth Identity Provider and OpenSAMLCVE-2016-5393Highorg.apache.hadoop:hadoop-common: Improper Access Control in Apache HadoopCVE-2014-3120Highorg.elasticsearch:elasticsearch: Elasticsearch Improper Access Control vulnerabilityCVE-2013-4271Highorg.restlet.jse:org.restlet: Restlet Arbitrary Java Code Execution via a serialized objectCVE-2010-1622Mediumorg.springframework:spring: Improper Control of Generation of Code ('Code Injection') in Spring FrameworkCVE-2013-4316Highorg.apache.struts:struts2-core: Code injection in Apache StrutsCVE-2013-4221Highorg.restlet.jse:org.restlet: Restlet is vulnerable to Arbitrary Java Code Execution via crafted XMLCVE-2013-1821Mediumorg.jruby:jruby: Ruby vulnerable to denial of serviceCVE-2015-6524Mediumorg.apache.activemq:activemq-broker: Improper Input Validation in Apache ActiveMQCVE-2013-2248Mediumorg.apache.struts:struts2-core: Open redirect in Apache StrutsCVE-2013-3827Mediumorg.glassfish:javax.faces: Path Traversal in Eclipse MojarraCVE-2010-5327Highcom.liferay.portal:portal-impl: Shell command injection in Liferay PortalCVE-2014-9527Mediumorg.apache.poi:poi: Loop with Unreachable Exit Condition in Apache POICVE-2016-3102Highorg.jenkins-ci.plugins:script-security: Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox ProtectionCVE-2012-1574Mediumorg.apache.hadoop:hadoop-main: Apache Hadoop allows impersonation of arbitrary cluster user accountsCVE-2012-3376Highorg.apache.hadoop:hadoop-client: Client BlockTokens not checked in Apache HadoopCVE-2013-2192Loworg.apache.hadoop:hadoop-common: Improper Authentication in Apache HadoopCVE-2014-0229Mediumorg.apache.hadoop:hadoop-common: Improper Authentication in Apache HadoopCVE-2016-4976Mediumorg.apache.ambari:ambari: Apache Ambari reveals administrator passwordsCVE-2016-6807Criticalorg.apache.ambari:ambari: Apache Ambari Improper Access ControlCVE-2015-1612Highorg.opendaylight.openflowplugin:openflowplugin: OpenFlow plugin for OpenDaylight LLDP RelayCVE-2017-5649Highorg.apache.geode:geode-core: Apache Geode information disclosure vulnerabilityCVE-2015-1611Highorg.opendaylight.openflowplugin:openflowplugin: OpenFlow plugin for OpenDaylight allows spoofing the SDN topology

Stop the waste.
Protect your environment with Kodem.