Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2014-8110Mediumorg.apache.activemq:activemq-client: Improper Neutralization of Input During Web Page Generation in Apache ActiveMQCVE-2015-1830Mediumorg.apache.activemq:activemq-client: Improper Limitation of a Pathname to a Restricted Directory in Apache ActiveMQCVE-2016-0734Mediumorg.apache.activemq:activemq-client: Improper Neutralization of Input During Web Page Generation in Apache ActiveMQCVE-2016-0782Mediumorg.apache.activemq:activemq-client: Improper Neutralization of Input During Web Page Generation in Apache ActiveMQCVE-2016-3088Criticalorg.apache.activemq:activemq-client: Improper Input Validation in Apache ActiveMQCVE-2018-19859Mediumorg.openrefine:main: OpenRefine Directory TraversalCVE-2014-3603Mediumedu.internet2.middleware:shibboleth-identityprovider: Improper Validation of Certificate with Host Mismatch in Shibboleth Identity Provider and OpenSAML JavaCVE-2014-8114Mediumorg.uberfire:uberfire-parent: UberFire Framework Improperly Restricts PathsCVE-2013-4286Mediumorg.apache.tomcat:tomcat: Apache Tomcat is vulnerable to HTTP request-smugglingCVE-2012-3544Mediumorg.apache.tomcat:tomcat: Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensionsCVE-2013-4322Mediumorg.apache.tomcat:tomcat: Apache Tomcat Denial of Service vulnerabilityCVE-2013-2067Mediumorg.apache.tomcat:tomcat: Improper Authentication in Apache TomcatCVE-2014-0033Mediumorg.apache.tomcat:tomcat: Improper Input Validation in Apache TomcatCVE-2013-4590Mediumorg.apache.tomcat:tomcat: Exposure of Sensitive Information to an Unauthorized Actor in Apache TomcatCVE-2014-0075Mediumorg.apache.tomcat:tomcat: Integer Overflow or Wraparound in Apache TomcatCVE-2014-0099Mediumorg.apache.tomcat:tomcat: Improper Neutralization of CRLF Sequences in HTTP Headers in Apache TomcatCVE-2014-0227Mediumorg.apache.tomcat:tomcat: Improper Input Validation in Apache TomcatCVE-2014-0096Mediumorg.apache.tomcat:tomcat: Improper Input Validation in Apache TomcatCVE-2014-0119Mediumorg.apache.tomcat:tomcat: Missing XML Validation in Apache TomcatCVE-2014-0230Highorg.apache.tomcat:tomcat: Uncontrolled Resource Consumption in Apache TomcatCVE-2016-0714Highorg.apache.tomcat:tomcat: Improper Access Control in Apache TomcatCVE-2014-7810Mediumorg.apache.tomcat:tomcat: Improper Access Control in Apache TomcatCVE-2016-0706Mediumorg.apache.tomcat:tomcat: Exposure of Sensitive Information to an Unauthorized Actor in Apache TomcatCVE-2016-6817Highorg.apache.tomcat:tomcat: Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache TomcatCVE-2015-5345Mediumorg.apache.tomcat:tomcat: Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

Stop the waste.
Protect your environment with Kodem.