Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-6348Mediumorg.jboss.resteasy:resteasy-client: JacksonJsonpInterceptor susceptible to cross-site script inclusion (XSSI) attackCVE-2016-6347Mediumorg.jboss.resteasy:resteasy-client: Improper Neutralization of Input During Web Page Generation in RESTEasyCVE-2011-2481Mediumorg.apache.tomcat:tomcat: Apache Tomcat Allows Replacing of XML ParserCVE-2013-2071Loworg.apache.tomcat:tomcat: Exposure of Sensitive Information to an Unauthorized Actor in Apache TomcatCVE-2017-7669Highorg.apache.hadoop:hadoop-common: Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validationCVE-2016-5004Mediumorg.apache.xmlrpc:xmlrpc-common: ws-xmlrpc DoS VulnerabilityCVE-2017-7667Highorg.apache.nifi:nifi: Origin Validation Error in Apache NiFi CVE-2017-7665Mediumorg.apache.nifi:nifi: Cross-site Scripting in Apache NiFiCVE-2016-6652Mediumorg.springframework.data:spring-data-jpa: Improper Neutralization of Special Elements used in an SQL Command Pivotal Spring Data JPACVE-2015-1778Criticalorg.opendaylight.odlparent:opendaylight-karaf-resources: Opendaylight will authenticate any username and password combinationCVE-2017-7666Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings vulnerable to Cross-Site Request ForgeryCVE-2017-7681Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings vulnerable to SQL injectionCVE-2017-7663Mediumorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings Cross-site Scripting vulnerabilityCVE-2017-7683Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings displays Tomcat version and detailed error stack traceCVE-2017-7664Criticalorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings does not correctly validate uploaded XML documentsCVE-2016-6798Criticalorg.apache.sling:org.apache.sling.xss: XML External Entity Reference in Apache SlingCVE-2017-1000362Criticalorg.jenkins-ci.main:jenkins-core: Exposure of Sensitive Information to an Unauthorized Actor in JenkinsCVE-2016-8741Highorg.apache.qpid:qpid-broker: Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for JavaCVE-2015-8796Mediumorg.apache.solr:solr: Apache Solr Cross-site scripting VulnerabilityCVE-2010-1632Highorg.apache.axis2.wso2:axis2: Improper Input Validation in Apache Axis2CVE-2015-3198Highorg.wildfly:wildfly-parent: The Undertow module of WildFly allows source code disclosureCVE-2008-5720Mediumcom.github.seasarorg.mayaa:mayaa: Mayaa Cross-site Scripting vulnerability CVE-2011-2730Highorg.springframework:spring-core: Improper Neutralization of Directives in Dynamically Evaluated Code in Spring FrameworkCVE-2016-4431Highorg.apache.struts:struts-parent: Apache Struts Access Control RedirectCVE-2016-4433Highorg.apache.struts.xwork:xwork-core: Apache Struts Open Redirect

Stop the waste.
Protect your environment with Kodem.