Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2015-5174Mediumorg.apache.tomcat:tomcat: Improper Limitation of a Pathname to a Restricted Directory in Apache TomcatCVE-2017-5647Highorg.apache.tomcat:tomcat: Exposure of Sensitive Information to an Unauthorized Actor in Apache TomcatCVE-2016-8745Highorg.apache.tomcat:tomcat-util: Concurrent Execution using Shared Resource with Improper Synchronization in Apache TomcatCVE-2017-12616Highorg.apache.tomcat:tomcat-catalina: Exposure of Sensitive Information to an Unauthorized Actor in Apache TomcatCVE-2016-8747Highorg.apache.tomcat:tomcat: Apache Tomcat allows remote attackers to read data that was intended to be associated with a different requestCVE-2017-15706Mediumorg.apache.tomcat:tomcat: Inconsistent documentation in Apache TomcatCVE-2017-7674Mediumorg.apache.tomcat:tomcat: Insufficient Verification of Data Authenticity in Apache TomcatCVE-2018-1999027Mediumorg.jenkins-ci.plugins:saltstack: Jenkins SaltStack Plugin allows attackers to capture credentials with a known credentials ID stored in JenkinsCVE-2018-1000191Mediumcom.synopsys.integration:synopsys-detect: Jenkins Black Duck Detect Plugin information exposure vulnerabilityCVE-2011-4969Mediumjquery: jQuery vulnerable to Cross-Site Scripting (XSS)CVE-2017-5657Highorg.apache.archiva:archiva: Apache Archiva vulnerable to Cross Site Request ForgeryCVE-2016-5005Mediumorg.apache.archiva:archiva: Apache Archiva vulnerable to Cross-site ScriptingCVE-2017-12617Highorg.apache.tomcat:tomcat-catalina: Unrestricted Upload of File with Dangerous Type Apache TomcatCVE-2019-1003010Mediumorg.jenkins-ci.plugins:git: Cross-Site Request Forgery in Jenkins Git PluginCVE-2018-10862Mediumorg.wildfly.core:wildfly-server: Improper Limitation of a Pathname to a Restricted Directory in WildFlyCVE-2016-6810Mediumorg.apache.activemq:activemq-client: Improper Neutralization of Input During Web Page Generation Apache ActiveMQCVE-2017-1000217Highorg.opencastproject:base: Opencast RCE VulnerabilityCVE-2016-4461Highorg.apache.struts:struts2-core: Apache Struts forced double OGNL evaluationCVE-2016-8748Mediumorg.apache.nifi:nifi: Cross-site Scripting in Apache NiFiCVE-2018-1999006Mediumorg.jenkins-ci.main:jenkins-core: Exposure of Sensitive Information to an Unauthorized Actor in JenkinsCVE-2018-1999046Mediumorg.jenkins-ci.main:jenkins-core: Exposure of Sensitive Information to an Unauthorized Actor in JenkinsCVE-2018-1999042Mediumorg.jenkins-ci.main:jenkins-core: Deserialization of Untrusted Data in JenkinsCVE-2018-1999045Mediumorg.jenkins-ci.main:jenkins-core: Improper Authentication in JenkinsCVE-2018-1000862Mediumorg.jenkins-ci.main:jenkins-core: Exposure of Sensitive Information to an Unauthorized Actor in JenkinsCVE-2018-1000409Mediumorg.jenkins-ci.main:jenkins-core: Session Fixation in Jenkins

Stop the waste.
Protect your environment with Kodem.