Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-5003Criticalorg.apache.xmlrpc:xmlrpc: Apache XML-RPC vulnerable to Deserialization of Untrusted DataCVE-2013-2033Mediumorg.jenkins-ci.main:jenkins-core: Jenkins vulnerable to Cross-site ScriptingCVE-2012-0838Highorg.apache.struts:struts2-core: Apache Struts Code injection due to conversion errorCVE-2018-11804Highorg.apache.spark:spark-core_2.11: Improper Input Validation in Apache SparkCVE-2014-3681Mediumorg.jenkins-ci.main:jenkins-core: Jenkins Cross-site Scripting vulnerabilityCVE-2018-17605Highorg.grails.plugins:asset-pipeline: Asset Pipeline plugin for Grails vulnerable to Path TraversalCVE-2018-19413Mediumorg.sonarsource.sonarqube:sonar-plugin-api: Exposure of Sensitive Information to an Unauthorized Actor in SonarSource SonarQube APICVE-2018-20227Highorg.eclipse.rdf4j:rdf4j: RDF4J vulnerable to zip slipCVE-2014-0219Mediumorg.apache.karaf:apache-karaf: Improper Input Validation in Apache KarafCVE-2018-20663Mediumcom.haulmont.cuba:cuba-web-toolkit: The Reporting Addon for CUBA Platform has Persistent XSSCVE-2018-1000413Mediumorg.jenkins-ci.plugins:config-file-provider: Stored XSS vulnerability in Config File Provider Plugin CVE-2019-5312Criticalcom.github.binarywang:weixin-java-common: XML External Entity Reference in weixin-java-toolsCVE-2018-1000414Highorg.jenkins-ci.plugins:config-file-provider: CSRF vulnerability in Config File Provider Plugin CVE-2018-1000417Highorg.jenkins-ci.plugins:email-ext: CSRF vulnerability in Email Extension Template Plugin CVE-2018-1000411Mediumorg.jenkins-ci.plugins:junit: Jenkins JUnit Plugin CSRF vulnerabilityCVE-2018-1330Highorg.apache.mesos:mesos: Crash when decoding malformed HTTP requests or malformed JSON payloadCVE-2018-1000422Mediumorg.jenkins-ci.plugins:crowd2: Jenkins Crowd 2 Integration Plugin server-side request forgery vulnerabilityCVE-2018-1000421Mediumorg.jenkins-ci.plugins:mesos: Server-side request forgery vulnerability in Jenkins Mesos PluginCVE-2018-1000415Mediumcom.sonyericsson.hudson.plugins.rebuild:rebuild: Cross-site Scripting in Jenkins Rebuilder PluginCVE-2013-5960Mediumorg.owasp.esapi:esapi: Missing Cryptographic Step in OWASP Enterprise Security API for JavaCVE-2019-7722Highnet.sourceforge.pmd:pmd-core: Improper Restriction of XML External Entity Reference in PMDCVE-2016-5016Mediumorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry vulnerable to Improper Certificate ValidationCVE-2018-8031Mediumorg.apache.tomee:tomee-webapp: Apache TomEE console vulnerable to Cross-site ScriptingCVE-2018-1306Highorg.apache.portals.pluto:pluto-container: Exposure of Sensitive Information in Apache PlutoCVE-2016-8736Criticalorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings RCE

Stop the waste.
Protect your environment with Kodem.