Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-8738Mediumorg.apache.struts:struts2-core: Apache Struts vulnerable to possible DoS attack when using URLValidatorCVE-2016-3090Highorg.apache.struts:struts2-parent: Apache Struts RCE VulnerabilityCVE-2018-1000182Mediumorg.jenkins-ci.plugins:git: Server-Side Request Forgery in Jenkins Git PluginCVE-2018-1000184Mediumcom.coravy.hudson.plugins.github:github: Jenkins GitHub Plugin server-side request forgery vulnerability existsCVE-2018-1000186Loworg.jenkins-ci.plugins:ghprb: Jenkins GitHub Pull Request Builder Plugin credential capture vulnerabilityCVE-2018-1000185Mediumorg.jenkins-ci.plugins:github-branch-source: Jenkins GitHub Branch Source Plugin vulnerable to Server-Side Request ForgeryCVE-2018-1000187Mediumorg.csanchez.jenkins.plugins:kubernetes: Exposure of Sensitive Information in Jenkins Kubernetes PluginCVE-2018-1000202Mediumorg.jvnet.hudson.plugins:groovy-postbuild: Jenkins Groovy Postbuild Plugin vulnerable to Cross-site ScriptingCVE-2018-1000183Mediumcom.coravy.hudson.plugins.github:github: Jenkins GitHub Plugin exposure of sensitive information vulnerability existsCVE-2018-1000188Mediumorg.jenkins-ci.plugins:cas-plugin: Jenkins CAS Plugin Server-Side Request Forgery vulnerabilityCVE-2018-1000198Mediumcom.blackducksoftware.integration:blackduck-hub: XML External Entity processing vulnerability in Jenkins Black Duck Hub PluginCVE-2018-1000190Mediumcom.blackducksoftware.integration:blackduck-hub: Exposure of sensitive information vulnerability in Jenkins Black Duck Hub PluginCVE-2018-1000196Mediumorg.jenkins-ci.ruby-plugins:gitlab-hook: Jenkins Gitlab Hook Plugin stores and displays GitLab API token in plain textCVE-2015-5346Highorg.apache.tomcat:tomcat: Improper Neutralization of Input During Web Page Generation in Apache TomcatCVE-2015-5351Highorg.apache.tomcat:tomcat: Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a tokenCVE-2018-12036Highorg.owasp:dependency-check-maven: Path Traversal in OWASP Dependency-CheckCVE-2018-12432Mediumnet.bull.javamelody:javamelody-core: Cross-site Scripting in JavaMelodyCVE-2018-1000601Mediumorg.jenkins-ci.plugins:ssh-credentials: Exposure of Sensitive Information to an Unauthorized Actor in Jenkins SSH Credentials PluginCVE-2018-1000602Mediumorg.jenkins-ci.plugins:saml: Jenkins SAML Plugin Session Fixation vulnerabilityCVE-2018-13003Mediumnet.opentsdb:opentsdb: OpenTSDB Cross-site Scripting vulnerabilityCVE-2018-12973Mediumnet.opentsdb:opentsdb: OpenTSDB Cross-site Scripting vulnerabilityCVE-2018-1000604Mediumorg.jenkins-ci.plugins:badge: Jenkins Badge Plugin cross-site scripting vulnerabilityCVE-2018-1000606Mediumorg.jenkins-ci.plugins:urltrigger: URLTrigger Plugin server-side request forgery vulnerabilityCVE-2018-1000607Mediumorg.jenkins-ci.plugins:fortify-cloudscan-jenkins-plugin: Arbitrary file write vulnerability in Jenkins Fortify CloudScan PluginCVE-2018-11041Mediumorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry UAA open redirect

Stop the waste.
Protect your environment with Kodem.