Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-10295Mediumorg.jenkins-ci.plugins:crittercism-dsym: Jenkins crittercism-dsym Plugin stores API key in plain textCVE-2019-10280Highorg.jenkins-ci.plugins:assembla-auth: Jenkins Assembla Auth Plugin stores credentials in plain text CVE-2016-6816Highorg.apache.tomcat:tomcat-coyote: Improper Input Validation in Apache TomcatCVE-2016-8735Criticalorg.apache.tomcat:tomcat-catalina: Apache Tomcat Improper Access Control vulnerabilityCVE-2018-1067Mediumorg.jboss.eap:wildfly-undertow: Improper Neutralization of CRLF Sequences in HTTP Headers in UndertowCVE-2010-1870Mediumorg.apache.struts:struts2-core: Server side object manipulation in Apache StrutsCVE-2015-1832Criticalorg.apache.derby:derby: Improper Restriction of XML External Entity Reference in Apace DerbyCVE-2013-2251Criticalorg.apache.struts:struts2-core: Code injection in Apache StrutsCVE-2019-1003030Criticalorg.jenkins-ci.plugins.workflow:workflow-cps: Sandbox bypass in Jenkins Pipeline: Groovy PluginCVE-2019-7611Highorg.elasticsearch:elasticsearch: Improper Access Control in ElasticsearchCVE-2016-2510Highorg.apache-extras.beanshell:bsh: Improper Input Validation in BeanShellCVE-2016-5000Mediumorg.apache.poi:poi-examples: Apache POI's XLSX2CSV Example XML External Entity (XXE) VulnerabilityCVE-2018-8013Criticalorg.apache.xmlgraphics:batik: Deserialization of Untrusted Data in Apache BatikCVE-2017-13098Mediumorg.bouncycastle:bcprov-jdk15on: Observable Discrepancy in BouncyCastleCVE-2017-9096Highcom.itextpdf:itextpdf: Improper Restriction of XML External Entity Reference in iTextCVE-2017-5644Mediumorg.apache.poi:poi: Improper Restriction of Recursive Entity References in DTDs in Apache POICVE-2017-5662Highorg.apache.xmlgraphics:batik: Improper Restriction of XML External Entity Reference in Apache BatikCVE-2017-2599Mediumorg.jenkins-ci.main:jenkins-core: Incorrect Authorization in JenkinsCVE-2018-14657Highorg.keycloak:keycloak-parent: Keycloak Improper Bruteforce DetectionCVE-2018-1048Highorg.jboss.eap:wildfly-undertow: Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP UndertowCVE-2018-14642Mediumio.undertow:undertow-core: Exposure of Sensitive Information to an Unauthorized Actor in UndertowCVE-2013-7398Mediumcom.ning:async-http-client: Insufficient Verification of Data Authenticity in Async Http ClientCVE-2013-7397Mediumcom.ning:async-http-client: Insufficient Verification of Data Authenticity in Async Http ClientCVE-2013-4444Mediumorg.apache.tomcat:tomcat: Apache Tomcat Unrestricted file upload vulnerabilityCVE-2017-8028Highorg.springframework.ldap:spring-ldap-core: Improper Authentication in Pivotal Spring-LDAP

Stop the waste.
Protect your environment with Kodem.