Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-4436Criticalorg.apache.struts:struts2-core: Apache Struts improper action name cleanupCVE-2016-4465Mediumorg.apache.struts:struts2-core: Apache Struts vulnerable to possible DoS attack when using URLValidatorCVE-2017-12648Mediumcom.liferay.portal:release.portal.bom: Liferay Portal XSS VulnerabilityCVE-2017-12647Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to XSS via a Knowledge Base Article TitleCVE-2017-9801Highorg.apache.commons:commons-email: Improper Input Validation in Apache Commons EmailCVE-2017-12646Mediumcom.liferay.portal:release.portal.bom: Liferay Portal XSS Vulnerability CVE-2017-12645Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to XSS via an Invalid portletIdCVE-2016-10404Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to XSS via a Crafted Redirect FieldCVE-2017-12649Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Vulnerable to XSS via Mishandled Title or Summary in the Web Content DisplayCVE-2008-6504Mediumcom.opensymphony:xwork: Improper Input Validation in OpenSymphony XWorkCVE-2011-1419Mediumorg.apache.tomcat:tomcat: Apache Tomcat does not follow ServletSecurity annotationsCVE-2013-4204Mediumcom.google.gwt:gwt: Improper Neutralization of Input During Web Page Generation in Google Web ToolkitCVE-2017-12881Highorg.springframework.batch:spring-batch-admin-manager: Spring Batch Admin vulnerable to Cross-site request forgery (CSRF) in the file upload functionalityCVE-2017-12882Mediumorg.springframework.batch:spring-batch-admin-manager: Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionalityCVE-2011-5245Mediumorg.jboss.resteasy:resteasy-jaxb-provider: Exposure of Sensitive Information to an Unauthorized Actor in RESTEasyCVE-2012-0818Mediumorg.jboss.resteasy:resteasy-client: Exposure of Sensitive Information to an Unauthorized Actor in RESTEasyCVE-2012-1006Mediumorg.apache.struts:struts2-parent: Apache Struts Multiple Cross-site Scripting VulnerabilitiesCVE-2012-3467Mediumorg.apache.qpid:qpid-parent: Apache QPID Allows Remote Authentication BypassCVE-2012-4387Mediumorg.apache.struts.xwork:xwork-core: Denial of service in Apache StrutsCVE-2012-4386Mediumorg.apache.struts:struts2-core: Cross-Site Request Forgery in Apache StrutsCVE-2012-5785Mediumorg.apache.axis2:axis2: Apache Axis2 has Improper Input ValidationCVE-2012-5817Highorg.codehaus.xfire:xfire-core: Improper Input Validation in XFireCVE-2012-5886Mediumorg.apache.tomcat:tomcat-catalina: Improper Authentication in Apache TomcatCVE-2012-5887Mediumorg.apache.tomcat:tomcat: Improper Authentication in Apache TomcatCVE-2013-1879Mediumorg.apache.activemq:activemq-client: Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ

Stop the waste.
Protect your environment with Kodem.