Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2007-2450Loworg.apache.tomcat:tomcat: Apache Tomcat vulnerable to Cross-site ScriptingCVE-2007-2449Mediumorg.apache.tomcat:tomcat: Apache Tomcat XSS Vulnerabilities in Examples Web ApplicationCVE-2007-2353Mediumorg.apache.axis:axis: Apache Axis allows Exposure of Sensitive Information to an Unauthorized ActorCVE-2007-1358Loworg.apache.tomcat:tomcat: Apache Tomcat XSS In Accept-Language HeadersCVE-2007-1355Mediumorg.apache.tomcat:jsp-api: Apache Tomcat Vulnerable to Cross-Site ScriptingCVE-2007-0450Mediumorg.apache.tomcat:tomcat: Apache Tomcat Directory TraversalCVE-2007-0185Highorg.directwebremoting:dwr: Direct Web Remoting vulnerable to Denial of ServiceCVE-2007-0184Highorg.directwebremoting:dwr: Incorrect Authorization in Getahead Direct Web RemotingCVE-2006-7223Mediumorg.xwiki.platform:xwiki-platform-oldcore: XWiki Remote Code ExecutionCVE-2006-7217Mediumorg.apache.derby:derby: Apache Derby SQL InjectionCVE-2006-7196Mediumorg.apache.tomcat:tomcat: Cross-site scripting in Apache TomcatCVE-2006-7197Highorg.apache.tomcat:tomcat: Apache Tomcat Buffer Over-ReadCVE-2006-7195Mediumorg.apache.tomcat:tomcat: Apache Tomcat XSS VulnerabilityCVE-2006-6969Mediumorg.eclipse.jetty:jetty-server: Jetty Uses Predictable Session IdentifiersCVE-2006-3936Mediumorg.opencms:opencms-core: Alkacon OpenCms Exposes JSP Source CodeCVE-2006-3935Mediumorg.opencms:opencms-core: Alkacon OpenCMS Improper Access Control via system/workplace/views/admin/admin-main.jspCVE-2006-3934Mediumorg.opencms:opencms-core: Alkacon OpenCMS Absolute Path Traversal via pathname in filePath parameterCVE-2006-3933Loworg.opencms:opencms-core: Alkacon OpenCms XSS via unsanitized message bodyCVE-2006-3835Mediumorg.apache.tomcat:tomcat: Apache Tomcat Reveals DirectoriesCVE-2006-2759Mediumorg.mortbay.jetty:jetty: Improper Input Validation in Mortbay Jetty CVE-2006-2758Mediumorg.mortbay.jetty:jetty: Jetty Directory Traversal VulnerabilityCVE-2006-2571Loworg.opencms:opencms-core: Alkacon OpenCms XSS via query parameter in a search actionCVE-2006-1546Highstruts:struts: Apache Struts vulnerable to Improper Input ValidationCVE-2006-1548Lowstruts:struts: Cross-site scripting in Apache StrutsCVE-2006-1547Highstruts:struts: Improper Input Validation in Apache Struts

Stop the waste.
Protect your environment with Kodem.