Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-3084Highorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry UAA reset password vulnerable to brute force attackCVE-2017-4960Highorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry denial of service vulnerabilityCVE-2015-5349Highorg.apache.directory.studio:org.apache.directory.studio.ldapbrowser.core: Apache Directory Studio Command InjectionCVE-2018-1256Highio.pivotal.spring.cloud:spring-cloud-sso-connector: Issuer validation regression in Spring Cloud SSO ConnectorCVE-2012-2098Mediumorg.apache.commons:commons-compress: Uncontrolled Resource Consumption in Apache Commons CompressCVE-2018-1263Mediumorg.springframework.integration:spring-integration-zip: spring-integration-zip Arbitrary File WriteCVE-2018-1262Highorg.cloudfoundry.identity:cloudfoundry-identity-server: UAA privilege escalation across identity zonesCVE-2015-3189Loworg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten PasswordCVE-2015-5171Criticalorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry Runtime Insufficient Session Expiration vulnerabilityCVE-2015-5170Highorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry Runtime Cross-Site Request Forgery vulnerabilityCVE-2015-5172Criticalorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten PasswordCVE-2019-6804Mediumorg.rundeck:rundeck: Rundeck Community Edition vulnerable to Cross-site ScriptingCVE-2016-0767Mediumpostgresql:pljava-public: PostgreSQL PL/Java Improper Privilege ManagementCVE-2018-8012Highorg.apache.zookeeper:zookeeper: Missing Authorization in Apache ZooKeeperCVE-2013-2172Mediumorg.apache.santuario:xmlsec: Inefficient Algorithmic Complexity in Apache Santuario XML SecurityCVE-2013-4517Mediumorg.apache.santuario:xmlsec: Improper Input Validation in Apache Santuario XML SecurityCVE-2014-8152Mediumorg.apache.santuario:xmlsec: Improper Input Validation in Apache Santuario XML SecurityCVE-2015-0886Mediumorg.mindrot:jbcrypt: Integer Overflow or Wraparound in JBCryptCVE-2014-0107Highxalan:xalan: Improper Authorization in Apache Xalan-JavaCVE-2014-3004Mediumorg.codehaus.castor:castor: Improper Restriction of XML External Entity Reference in CastorCVE-2019-1003004Highorg.jenkins-ci.main:jenkins-core: Improper Authorization in Jenkins CoreCVE-2019-1003003Highorg.jenkins-ci.main:jenkins-core: Improper Authorization in Jenkins CoreCVE-2019-0204Highorg.apache.mesos:mesos: Docker image code execution with Apache MesosCVE-2018-8088Criticalorg.slf4j:slf4j-ext: Improper Access Control in SLF4JCVE-2013-6440Mediumorg.opensaml:opensaml: Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML

Stop the waste.
Protect your environment with Kodem.