Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-4978Highorg.apache.activemq:artemis-pom: Apache ActiveMQ Artemis RCE Via Deserialization Gadget ChainCVE-2017-1000487Criticalorg.codehaus.plexus:plexus-utils: OS Command Injection in Plexus-utilsCVE-2017-12174Highorg.hornetq:hornetq-server: Uncontrolled Resource Consumption in Artemis and HornetQCVE-2016-2402Mediumcom.squareup.okhttp3:okhttp: Improper Certificate Validation in OkHttpCVE-2016-4970Highio.netty:netty-handler: Loop with Unreachable Exit Condition in NettyCVE-2016-10027Mediumorg.igniterealtime.smack:smack-core: Smack allows the bypass of TLS protectionsCVE-2017-15709Loworg.apache.activemq:activemq-openwire-generator: ActiveMQ's OpenWire protocol exposes certain system details as plain textCVE-2017-5646Mediumorg.apache.knox:gateway-provider-identity-assertion-common: Apache Knox allows impersonation of usersCVE-2015-2944Mediumorg.apache.sling:org.apache.sling.api: Improper Neutralization of Input During Web Page Generation in Apache SlingCVE-2012-5783Mediumcommons-httpclient:commons-httpclient: Improper Certificate Validation in Apache Commons HttpClientCVE-2018-1190Mediumorg.cloudfoundry.identity:cloudfoundry-identity-server: Pivotal Cloud Foundry UAA XSS on UAA OpenID Connect check session iframe endpointCVE-2017-8031Mediumorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry UAA Denial of Service through client token revocation endpointCVE-2015-5258Highorg.springframework.social:spring-social-core: springframework-social Cross-Site Request Forgery vulnerabilityCVE-2016-5725Mediumcom.jcraft:jsch: Improper Limitation of a Pathname to a Restricted Directory in JCraft JSchCVE-2010-2076Highorg.apache.cxf:cxf-rt-frontend-jaxrs: Improper Input Validation in Apache CXFCVE-2012-0803Criticalorg.apache.cxf:cxf: Improper Authentication in Apache CXFCVE-2012-2379Highorg.apache.cxf:cxf: XML Signature/Encryption Not Validated in Apache CXFCVE-2012-2378Mediumorg.apache.cxf:cxf: Improper Authentication in Apache CXFCVE-2017-3156Highorg.apache.cxf.karaf:apache-cxf: Covert Timing Channel in Apache CXFCVE-2012-5633Mediumorg.apache.cxf:cxf: Improper Authentication in Apache CXFCVE-2012-3451Highorg.apache.cxf:cxf: Remote web-service operation execution in Apache CXFCVE-2012-5575Mediumorg.apache.cxf:cxf-rt-transports-http: Inadequate Encryption Strength in Apache CXFCVE-2014-0034Mediumorg.apache.cxf:cxf-rt-ws-security: Improper Input Validation in Apache CXFCVE-2014-3623Mediumorg.apache.ws.security:wss4j: Improper Authentication in Apache WSS4JCVE-2017-12624Mediumorg.apache.cxf:cxf-core: Improper Input Validation in Apache CXF

Stop the waste.
Protect your environment with Kodem.