Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2013-0327Mediumorg.jenkins-ci.main:jenkins-core: Jenkins Cross-Site Request Forgery vulnerabilityCVE-2013-0330Mediumorg.jenkins-ci.main:jenkins-core: Jenkins allows Remote Users to Build Arbitrary JobsCVE-2013-0328Mediumorg.jenkins-ci.main:jenkins-core: Jenkins subject to Cross-site ScriptingCVE-2013-0248Lowcommons-fileupload:commons-fileupload: Incorrect Default Permissions in Apache Commons FileUploadCVE-2013-0239Mediumorg.apache.cxf:cxf-rt-frontend-jaxrs: Improper Authentication in Apache CXFCVE-2013-0158Loworg.jenkins-ci.main:jenkins-core: Jenkins allows attackers to obtain the master cryptographic keyCVE-2013-6430Mediumorg.springframework:spring-web: Improper Neutralization of Input During Web Page Generation in Spring FrameworkCVE-2022-28111Criticalcom.github.pagehelper:pagehelper: MyBatis PageHelper vulnerable to time-blind SQL injection via orderBy parameterCVE-2012-0394Mediumorg.apache.struts.xwork:xwork-core: Apache Struts's DebuggingInterceptor component allows remote code execution in developer modeCVE-2012-0392Mediumorg.apache.struts:struts2-core: Apache Struts's CookieInterceptor component does not use the parameter-name whitelistCVE-2012-0391Criticalorg.apache.struts:struts2-core: Apache Struts Remote Java Code ExecutionCVE-2012-0393Mediumorg.apache.struts.xwork:xwork-core: Apache Struts's ParameterInterceptor component does not prevent access to public constructorsCVE-2012-0325Loworg.jenkins-ci.main:jenkins-core: Jenkins allows Cross-Site Scripting (XSS)CVE-2012-0324Loworg.jenkins-ci.main:jenkins-core: Jenkins allows Cross-Site Scripting (XSS)CVE-2012-0213Mediumorg.apache.poi:poi: Denial of Service in Apache POICVE-2012-0022Mediumorg.apache.tomcat:tomcat: Denial of Service in Apache TomcatCVE-2011-0013Mediumorg.apache.tomcat:tomcat: Improper Neutralization of Input During Web Page Generation in Apache TomcatCVE-2022-25645Mediumdset: Prototype Pollution in dsetCVE-2022-25647Highcom.google.code.gson:gson: Deserialization of Untrusted Data in GsonCVE-2021-40822Highorg.geoserver:gs-main: GeoServer allows SSRF via the option for setting a proxy hostCVE-2022-25767Criticalcom.bstek.ureport:ureport2-console: Deserialization of Untrusted Data in com.bstek.ureport:ureport2-consoleCVE-2022-25842Mediumcom.alibaba.oneagent:one-java-agent-plugin: Path Traversal in com.alibaba.oneagent:one-java-agent-pluginCVE-2010-1330Mediumorg.jruby:jruby-core: Cross-site Scripting in in JRubyCVE-2010-1244Mediumorg.apache.activemq:activemq-parent: Cross-site request forgery in Apache ActiveMQCVE-2010-1157Mediumorg.apache.tomcat:tomcat: Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

Stop the waste.
Protect your environment with Kodem.