Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-2141Criticalorg.jgroups:jgroups: Improper Input Validation in JGroupsCVE-2017-8046Criticalorg.springframework.data:spring-data-rest-core: Remote code execution in PATCH requests in Spring Data RESTCVE-2013-6429Mediumorg.springframework:spring-web: Cross-Site Request Forgery in Spring FrameworkCVE-2014-3625Mediumorg.springframework:spring-webmvc: Improper Limitation of a Pathname to a Restricted Directory in Spring FrameworkCVE-2014-0225Highorg.springframework:spring-webmvc: Improper Restriction of XML External Entity Reference in Spring FrameworkCVE-2013-4152Mediumorg.springframework:spring-oxm: Cross-Site Request Forgery in Spring FrameworkCVE-2014-0054Mediumorg.springframework:spring-webmvc: Cross-Site Request Forgery in Spring FrameworkCVE-2013-7315Mediumorg.springframework:spring-oxm: Missing XML Validation in Spring FrameworkCVE-2017-2601Mediumorg.jenkins-ci.main:jenkins-core: Cross-site Scripting in JenkinsCVE-2018-1288Mediumorg.apache.kafka:kafka: Improper Control of Generation of Code in Apache KafkaCVE-2018-1313Mediumorg.apache.derby:derby: Improper Access Control in Apache DerbyCVE-2016-6794Mediumorg.apache.tomcat:tomcat: System Property Disclosure in Apache TomcatCVE-2017-4995Highorg.springframework.security:spring-security-core: Deserialization of Untrusted Data in Spring SecurityCVE-2016-6796Highorg.apache.tomcat:tomcat: Apache Tomcat vulnerable to SecurityManager bypassCVE-2016-6797Highorg.apache.tomcat:tomcat: Incorrect Authorization in Apache TomcatCVE-2016-5018Criticalorg.apache.tomcat:tomcat-jasper: Authentication Bypass Using an Alternate Path or Channel in Apache TomcatCVE-2016-0762Mediumorg.apache.tomcat:tomcat: Observable Discrepancy in Apache TomcatCVE-2017-17837Mediumorg.apache.deltaspike.modules:jsf-module-project: Cross-site Scripting in Apache DeltaSpikeCVE-2017-5641Criticalorg.apache.flex.blazeds:flex-messaging-core: Apache Flex BlazeDS unsafe deserializationCVE-2013-4002Highxerces:xercesImpl: Missing XML Validation in Apache Xerces2CVE-2014-0097Highorg.springframework.security:spring-security-core: Improper Authentication in Spring SecurityCVE-2012-5351Mediumorg.apache.axis2:axis2: Improper Authentication in Apache Axis2CVE-2017-1000353Criticalorg.jenkins-ci.main:jenkins-core: Deserialization of Untrusted Data in JenkinsCVE-2018-1000067Mediumorg.jenkins-ci.main:jenkins-core: Server-Side Request Forgery in JenkinsCVE-2018-1999007Mediumorg.jenkins-ci.main:jenkins-core: Cross-site scripting vulnerability exists in Jenkins and Stapler Plugin

Stop the waste.
Protect your environment with Kodem.