Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-8718Highorg.jenkins-ci.plugins:mailer: Cross-Site Request Forgery in Jenkins Mailer PluginCVE-2018-1294Highorg.apache.commons:commons-email: Improper Input Validation Apache Commons EmailCVE-2018-1000129Mediumorg.jolokia:jolokia-core: Cross-site Scripting in Jolokia agentCVE-2011-4461Mediumorg.eclipse.jetty:jetty-server: Improper Input Validation in JettyCVE-2018-1000130Highorg.jolokia:jolokia-core: Injection in Jolokia agentCVE-2017-9803Highorg.apache.solr:solr-core: Apache Solr Kerberos delegation token functionality flawsCVE-2014-3490Highorg.jboss.resteasy:resteasy-client: Incorrect Privilege Assignment in RESTEasyCVE-2014-3558Mediumorg.hibernate:hibernate-validator: Improper Authentication in Hibernate ValidatorCVE-2014-0111Mediumorg.apache.syncope:syncope: Apache Syncope JEXL Code InjectionCVE-2016-0763Mediumorg.apache.tomcat:tomcat: Improper Verification of Source of a Communication Channel in Apache TomcatCVE-2008-5515Mediumorg.apache.tomcat:tomcat: Directory Traversal in Apache TomcatCVE-2011-2526Mediumorg.apache.tomcat:tomcat: Improper Input Validation in Apache TomcatCVE-2011-2204Mediumorg.apache.tomcat:tomcat: Insertion of Sensitive Information into Log File in Apache TomcatCVE-2011-5062Mediumorg.apache.tomcat:tomcat: Improper Authentication in Apache TomcatCVE-2011-5064Mediumorg.apache.tomcat:tomcat: Use of Hard-coded Cryptographic Key in Apache TomcatCVE-2010-2227Mediumorg.apache.tomcat:tomcat: Apache Tomcat does not properly handle an invalid Transfer-Encoding headerCVE-2011-5063Mediumorg.apache.tomcat:tomcat: Improper Authentication in Apache TomcatCVE-2010-3718Loworg.apache.tomcat:tomcat: Improper Limitation of a Pathname to a Restricted Directory in Apache TomcatCVE-2011-1184Mediumorg.apache.tomcat:tomcat: Authentication Bypass in Apache TomcatCVE-2011-3190Highorg.apache.tomcat:tomcat: Apache Tomcat Allows Remote Attackers to Spoof AJP RequestsCVE-2014-1904Mediumorg.springframework:spring-webmvc: Improper Neutralization of Input During Web Page Generation in Spring FrameworkCVE-2014-3576Highorg.apache.activemq:activemq-client: Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQCVE-2014-3579Criticalorg.apache.activemq:apollo-project: Apache ActiveMQ Apollo XXE VulnerabilityCVE-2014-3600Criticalorg.apache.activemq:activemq-client: Improper Restriction of XML External Entity Reference in Apache ActiveMQCVE-2014-3612Highorg.apache.activemq:activemq-broker: Improper Authentication in Apache WSS4J

Stop the waste.
Protect your environment with Kodem.