Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2014-7809Mediumorg.apache.struts:struts2-core: Cross-Site Request Forgery in Apache StrutsCVE-2015-0225Highorg.apache.cassandra:apache-cassandra: Improper Neutralization of Special Elements used in a Command in Apache CassandraCVE-2015-1427Highorg.elasticsearch:elasticsearch: Improper Access Control in ElasticsearchCVE-2015-1833Mediumorg.apache.jackrabbit:jackrabbit-core: Improper Input Validation in Apache JackrabbitCVE-2015-2351Loworg.opencms:opencms-core: Alkacon OpenCMS XSS via homelink, workplaceresource, mode and query parametersCVE-2015-3188Criticalorg.apache.storm:storm: Apache Storm remote code execution vulnerabilityCVE-2015-4165Highorg.elasticsearch:elasticsearch: Improper Access Control in ElasticsearchCVE-2015-5531Mediumorg.elasticsearch:elasticsearch: Improper Limitation of a Pathname to a Restricted Directory in ElasticsearchCVE-2015-7611Highorg.apache.james:james-server: Apache James Server OS Command InjectionCVE-2016-0784Mediumorg.apache.openmeetings:openmeetings-install: Apache OpenMeetings Directory Traversal vulnerabilityCVE-2016-0956Highorg.apache.sling:org.apache.sling.servlets.post: Exposure of Sensitive Information to an Unauthorized Actor in Apache Sling Servlets PostCVE-2016-2163Mediumorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings Cross-site Scripting vulnerabilityCVE-2016-2164Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings allows remote attackers to read arbitrary files by attempting to upload a fileCVE-2016-3089Mediumorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings Cross-site Scripting vulnerabilityCVE-2016-4314Mediumorg.wso2.carbon.commons:org.wso2.carbon.logging.view.ui: WSO2 Carbon directory traversal vulnerabilityCVE-2016-4316Mediumorg.wso2.carbon.commons:org.wso2.carbon.ndatasource.ui: WSO2 Carbon vulnerable to Cross-site ScriptingCVE-2016-4437Criticalorg.apache.shiro:shiro-core: Improper Access Control in Apache ShiroCVE-2016-4974Highorg.apache.qpid:qpid-jms-client: Improper Input Validation in Apache Qpid AMQP 0-x JMSCVE-2016-6802Highorg.apache.shiro:shiro-all: Improper Access Control in Apache ShiroCVE-2017-9802Mediumorg.apache.sling:org.apache.sling.servlets.post: Improper Neutralization of Input During Web Page Generation Apache Sling Servlets PostCVE-2018-1999037Loworg.jenkins-ci.plugins:resource-disposer: Jenkins Resource Disposer Plugin allows attacker to stop tracking specified resourceCVE-2010-1587Mediumorg.apache.activemq:activemq-web-console: Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandlerCVE-2010-2103Mediumorg.apache.axis2.wso2:axis2: Improper Neutralization of Input During Web Page Generation in Apache Axis2CVE-2010-3700Mediumorg.springframework.security:spring-security-core: Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi SecurityCVE-2010-3863Mediumorg.apache.shiro:shiro-root: Apache Shiro Path Traversal vulnerability

Stop the waste.
Protect your environment with Kodem.