Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-1000057Mediumorg.jenkins-ci.plugins:credentials-binding: Jenkins Credentials Binding Plugin has Insufficiently Protected CredentialsCVE-2017-9797Mediumorg.apache.geode:geode-core: Apache Geode vulnerable to Exposure of Sensitive InformationCVE-2017-9790Highorg.apache.mesos:mesos: Use after free in Apache MesosCVE-2017-8039Mediumorg.springframework.webflow:spring-webflow: Insecure Default Initialization of Resource in Pivotal Spring Web FlowCVE-2017-7684Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings vulnerable to Uncontrolled Resource ConsumptionCVE-2017-7687Highorg.apache.mesos:mesos: Denial of service in Apache MesosCVE-2017-7688Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings updates user password in insecure mannerCVE-2017-7685Mediumorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings responds to insecure HTTP methodsCVE-2017-7673Criticalorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings has Inadequate Encryption StrengthCVE-2017-7682Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings vulnerable to parameter manipulation attacksCVE-2017-7680Highorg.apache.openmeetings:openmeetings-parent: Apache OpenMeetings allows flash content to be loaded from untrusted domainsCVE-2017-7561Highorg.jboss.resteasy:resteasy-jaxrs: Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAPCVE-2017-5664Highorg.apache.tomcat:tomcat: Improper Handling of Exceptional Conditions in Apache TomcatCVE-2017-5650Highorg.apache.tomcat:tomcat: Improper Resource Shutdown or Release in Apache TomcatCVE-2017-5651Criticalorg.apache.tomcat:tomcat-coyote: Expected Behavior Violation in Apache TomcatCVE-2017-5635Highorg.apache.nifi:nifi: Improper Authentication In Apache NiFiCVE-2017-4971Mediumorg.springframework.webflow:spring-webflow: Insecure Default Initialization of Resource in Pivotal Spring Web FlowCVE-2017-3589Lowmysql:mysql-connector-java: Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors JavaCVE-2017-3586Mediummysql:mysql-connector-java: Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors JavaCVE-2017-3523Highmysql:mysql-connector-java: Improper Access Control in MySQL Connectors JavaCVE-2017-13763Highorg.onosproject:onos-base: ONOS vulnerable to denial of service due to unrestricted NettyMessagingManager payloadCVE-2017-12973Lowcom.nimbusds:nimbus-jose-jwt: Nimbus JOSE+JWT vulnerable to padding oracle attackCVE-2017-1000403Highorg.jvnet.hudson.plugins:speaks: Arbitrary code execution vulnerability in Jenkins Speaks! PluginCVE-2017-1000387Highorg.jenkins-ci.plugins:build-publisher: Jenkins Build-Publisher plugin has Insufficiently Protected CredentialsCVE-2017-1000360Mediumorg.opendaylight.controller:releasepom: OpenDaylight NULL Pointer Dereference

Stop the waste.
Protect your environment with Kodem.