Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-5648Criticalorg.apache.tomcat:tomcat-catalina: Exposure of Resource to Wrong Sphere in Apache TomcatCVE-2011-1571Mediumcom.liferay.portal:portal-service: Liferay Portal vulnerable to arbitrary command injectionCVE-2013-4366Criticalorg.apache.httpcomponents:httpclient: Hostname verification in Apache HttpClient 4.3 was disabled by defaultCVE-2011-4367Mediumorg.apache.myfaces.core:myfaces-impl: Apache MyFaces Vulnerable to Path TraversalCVE-2016-5388Highorg.apache.tomcat:tomcat-catalina: Improper Access Control in Apache TomcatCVE-2017-12160Highorg.keycloak:keycloak-parent: Keycloak Oauth Implementation ErrorCVE-2019-6986Highorg.vivoweb:vitro-project: Command Injection in VIVO VitroCVE-2019-11065Mediumorg.gradle:gradle-core: Insecure transport protocol in GradleCVE-2018-8015Highorg.apache.orc:orc: Apache ORC vulnerable to Uncontrolled RecursionCVE-2018-18240Criticalro.pippo:pippo-core: Pippo RCE VulnerabilityCVE-2018-12532Criticalorg.richfaces:richfaces-core: RichFaces vulnerable to Expression Language InjectionCVE-2018-12533Criticalorg.richfaces:richfaces-core: Arbitrary code execution in RichfacesCVE-2018-1000412Mediumorg.jenkins-ci.plugins:jira: Jenkins Jira Plugin Incorrect Authorization vulnerabilityCVE-2018-1000418Highorg.jvnet.hudson.plugins:hipchat: Jenkins HipChat Plugin allows credential capture due to incorrect authorizationCVE-2018-1000425Highorg.jenkins-ci.plugins:sonar: Jenkins SonarQube Scanner Plugin stored server authentication token in plain textCVE-2018-1000424Highorg.jenkins-ci.plugins:artifactory: Jenkins Artifactory Plugin stored old directly entered credentials unencrypted on disk CVE-2018-1000419Mediumorg.jvnet.hudson.plugins:hipchat: Jenkins HipChat Plugin allows attackers with Overall/Read access to obtain credential IDsCVE-2018-1000423Highorg.jenkins-ci.plugins:crowd2: Jenkins Crowd 2 Integration Plugin stored credentials in plain text CVE-2018-1000149Mediumorg.jenkins-ci.plugins:ansible: Jenkins Ansible Plugin man in the middle vulnerabilityCVE-2018-1000073Highrubygems-update: RubyGems Link Following vulnerabilityCVE-2018-1000015Mediumorg.jenkins-ci.plugins.workflow:workflow-durable-task-step: Incorrect permission checks in Pipeline: Nodes and Processes pluginCVE-2017-1000390Mediumorg.jenkins-ci.plugins:jenkins-multijob-plugin: Jenkins Multijob plugin did not check permissions in the Resume Build actionCVE-2017-1000105Mediumio.jenkins.blueocean:blueocean: Missing Authorization in Jenkins Blue Ocean PluginCVE-2017-1000388Mediumorg.jenkins-ci.plugins:depgraph-view: Jenkins Dependency Graph Viewer plugin vulnerable to missing permission checksCVE-2017-15695Highorg.apache.geode:geode-core: Apache Geode vulnerable to Incorrect Authorization

Stop the waste.
Protect your environment with Kodem.