Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2013-2160Mediumorg.apache.cxf:cxf-rt-frontend-jaxrs: Missing XML Validation in Apache CXFCVE-2016-8739Highorg.apache.cxf:cxf-core: Improper Restriction of XML External Entity Reference in Apache CXF JAX-RSCVE-2014-0110Mediumorg.apache.cxf:cxf-core: Uncontrolled Resource Consumption in Apache CXFCVE-2015-5253Mediumorg.apache.cxf:cxf-rt-rs-security-sso-saml: Improper Access Control in Apache CXFCVE-2014-3584Mediumorg.apache.cxf:cxf-rt-frontend-jaxrs: Loop with Unreachable Exit Condition in Apache CXFCVE-2016-6812Mediumorg.apache.cxf:cxf-core: Improper Neutralization of Input During Web Page Generation in Apache CXFCVE-2014-0109Mediumorg.apache.cxf:cxf-core: Uncontrolled Resource Consumption in Apache CXFCVE-2014-0035Mediumorg.apache.cxf:cxf-core: Cleartext Transmission of Sensitive Information in Apache CXFCVE-2017-5656Highorg.apache.cxf:cxf-core: Session Fixation in Apache CXFCVE-2017-7662Highorg.apache.cxf.fediz:fediz-oidc: Cross-Site Request Forgery in Apache CXF FedizCVE-2017-5653Mediumorg.apache.cxf:cxf-core: Improper Certificate Validation in Apache CXFCVE-2017-3162Highorg.apache.hadoop:hadoop-client: Improper Input Validation in Apache HadoopCVE-2017-3161Mediumorg.apache.hadoop:hadoop-client: Improper Neutralization of Input During Web Page Generation in Apache HadoopCVE-2016-5001Mediumorg.apache.hadoop:hadoop-common: Exposure of Sensitive Information to an Unauthorized Actor in Apache HadoopCVE-2017-5637Highorg.apache.zookeeper:zookeeper: Uncontrolled Resource Consumption in Apache ZooKeeperCVE-2019-5919Criticalcom.nablarch.framework:nablarch-fw-web: Nablarch Incomplete CryptographyCVE-2018-14040Mediumbootstrap: Bootstrap vulnerable to Cross-Site Scripting (XSS)CVE-2017-5661Highorg.apache.xmlgraphics:fop: Improper Restriction of XML External Entity Reference in Apache FOPCVE-2011-5034Highorg.apache.geronimo:geronimo: Apache Geronimo Hash Collisions Cause DoSCVE-2016-6637Criticalorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry vulnerable to Cross-Site Request ForgeryCVE-2017-8032Mediumorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry UAA Identity Zone Admin Privilege EscalationCVE-2017-4974Mediumorg.cloudfoundry.identity:cloudfoundry-identity-server: Blind SQL Injection with privileged Cloud Foundry UAA endpointsCVE-2017-4991Highorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry UAA password reset vulnerabilityCVE-2017-4973Highorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry UAA Privilege EscalationCVE-2017-4992Criticalorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry UAA privilege escalation with user invitations

Stop the waste.
Protect your environment with Kodem.