Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2013-2254Mediumorg.apache.sling:org.apache.sling.api: Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache SlingCVE-2013-5573Loworg.jenkins-ci.main:jenkins-core: Jenkins allows Cross-Site Scripting (XSS) in User ConfigurationCVE-2014-2059Mediumorg.jenkins-ci.main:jenkins-core: Jenkins directory traversal vulnerabilityCVE-2014-2067Mediumorg.jenkins-ci.main:jenkins-core: Jenkins cross-site scripting (XSS) vulnerabilityCVE-2014-3529Mediumorg.apache.poi:poi: Improper Restriction of XML External Entity Reference in Apache POICVE-2014-3574Mediumorg.apache.poi:poi: Improper Input Validation in Apache POICVE-2014-3664Mediumorg.jenkins-ci.main:jenkins-core: Jenkins Path Traversal vulnerabilityCVE-2017-3150Mediumorg.apache.atlas:atlas-common: Insecure cookie storage in Apache Atlas CVE-2016-8752Highorg.apache.atlas:atlas-common: Path Traversal in Apache AtlasCVE-2017-3152Mediumorg.apache.atlas:atlas-common: Cross-site Scripting in Apache Atlas CVE-2017-3153Mediumorg.apache.atlas:atlas-common: Cross-site Scripting in Apache Atlas CVE-2017-3154Highorg.apache.atlas:atlas-common: Apache Atlas produces Stack trace in error responseCVE-2017-3155Mediumorg.apache.atlas:atlas-common: Cross-site Scripting in Apache Atlas CVE-2016-3086Criticalorg.apache.hadoop:hadoop-yarn-server-nodemanager: Exposure of Sensitive Information to an Unauthorized Actor in Apache HadoopCVE-2011-1475Mediumorg.apache.tomcat:tomcat: Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote UsersCVE-2012-3546Mediumorg.apache.tomcat:tomcat: Authentication Bypass in Apache TomcatCVE-2012-4431Mediumorg.apache.tomcat:tomcat: Cross-Site Request Forgery in Apache TomcatCVE-2012-5885Mediumorg.apache.tomcat:tomcat: Improper Access Control in Apache TomcatCVE-2015-3250Highorg.apache.directory.api:api-ldap-model: Exposure of Sensitive Information to an Unauthorized Actor in Apache Directory LDAP APICVE-2016-8737Highorg.apache.brooklyn:brooklyn-rest-resources: Apache Brooklyn is vulnerable to cross-site request forgery (CSRF)CVE-2014-9635Mediumorg.jenkins-ci.main:jenkins-core: Jenkins HttpOnly flag not Set for session cookiesCVE-2014-9634Mediumorg.jenkins-ci.main:jenkins-core: Jenkins secure flag not set on session cookiesCVE-2015-1831Highorg.apache.struts:struts2-core: Incomplete exclude pattern in Apache StrutsCVE-2017-3165Mediumorg.apache.brooklyn:brooklyn: Cross-site Scripting In Apache BrooklynCVE-2016-8744Highorg.apache.brooklyn:brooklyn: Deserialization of Untrusted Data in Apache Brooklyn

Stop the waste.
Protect your environment with Kodem.