Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-1000386Mediumorg.biouno:uno-choice: Cross-site Scripting in Jenkins Active Choices pluginCVE-2017-7675Highorg.apache.tomcat:tomcat: Improper Limitation of a Pathname to a Restricted Directory in Apache TomcatCVE-2017-1000113Mediumorg.jenkins-ci.plugins:deploy: Jenkins Deploy to container Plugin stored plain text passwords in job configurationCVE-2018-1325Mediumcom.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent: Cross-site Scripting in wicket-jquery-uiCVE-2017-15719Mediumcom.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent: Cross-site Scripting in wicket-jquery-uiCVE-2017-15691Mediumorg.apache.uima:uimafit-core: Improper Restriction of XML External Entity Reference in Apache uimajCVE-2018-11688Mediumorg.igniterealtime.openfire:parent: Ignite Realtime Openfire vulnerable to cross-site scriptingCVE-2017-9795Highorg.apache.geode:geode-core: Apache Geode OQL method invocation vulnerabilityCVE-2014-3578Mediumorg.springframework:spring-core: Improper Limitation of a Pathname to a Restricted Directory in Spring FrameworkCVE-2015-0226Highorg.apache.ws.security:wss4j: Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4JCVE-2017-1000190Criticalorg.simpleframework:simple-xml: SimpleXML has XML External Entity (XXE) vulnerabilityCVE-2018-1000169Mediumorg.jenkins-ci.main:jenkins-core: Exposure of Sensitive Information to an Unauthorized Actor in JenkinsCVE-2014-0112Highorg.apache.struts:struts2-core: ClassLoader manipulation in Apache StrutsCVE-2014-0094Mediumorg.apache.struts:struts2-core: ClassLoader manipulation in Apache StrutsCVE-2013-1966Highorg.apache.struts:struts2-core: Arbitrary code execution in Apache StrutsCVE-2013-1965Highorg.apache.struts:struts2-core: Improper Control of Generation of Code in Apache StrutsCVE-2014-0113Highorg.apache.struts:struts2-core: ClassLoader manipulation in Apache StrutsCVE-2016-3081Highorg.apache.struts:struts2-core: Apache Struts RCE VulnerabilityCVE-2016-3087Criticalorg.apache.struts:struts2-core: Apache Struts vulnerable to arbitrary remote code execution due to improper input validationCVE-2014-0116Highorg.apache.struts:struts2-core: ClassLoader manipulation in Apache StrutsCVE-2016-4438Criticalorg.apache.struts:struts2-core: Arbitrary code execution in Apache Struts 2CVE-2016-6795Criticalorg.apache.struts:struts2-convention-plugin: Path Traversal in Apache StrutsCVE-2018-1000416Mediumorg.jenkins-ci.plugins:jobConfigHistory: Jenkins Job Config History Plugin reflected XSS vulnerabilityCVE-2016-0785Highorg.apache.struts:struts2-core: Apache Struts RCE VulnerabilityCVE-2013-5823Mediumorg.apache.santuario:xmlsec: Apache XML Security For Java vulnerable to Infinite Loop

Stop the waste.
Protect your environment with Kodem.