Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2006-0254Mediumgeronimo:geronimo-console-standard: Apache Geronimo console 1.0 vulnerable to cross-site scriptingCVE-2005-4849Mediumorg.apache.derby:derby: Apache Derby exposes user and password attributesCVE-2005-4836Highorg.apache.tomcat:tomcat: Apache Tomcat allows remote attackers to read JSP source filesCVE-2005-4703Mediumorg.apache.tomcat:tomcat: Apache Tomcat Discloses MS-DOS PathnameCVE-2005-4294Loworg.opencms:opencms-core: Alkacon OpenCms XSS via username during loginCVE-2005-3747Mediumorg.mortbay.jetty:jetty: Mortbay Jetty Discloses JSP Source CodeCVE-2005-3745Mediumorg.apache.struts:struts-core: Apache Struts Cross-site scripting VulnerabilityCVE-2005-3510Highorg.apache.tomcat:tomcat: Apache Tomcat Vulnerable to Denial of Service (DoS) via Simultaneous RequestsCVE-2005-3164Loworg.apache.tomcat:tomcat: Apache Tomcat AJP Connector Information LeakCVE-2005-2090Mediumorg.apache.tomcat:tomcat: Tomcat Vulnerable to Web Cache PoisoningCVE-2022-29265Highorg.apache.nifi:nifi: Multiple components in Apache NiFi do not restrict XML External Entity referencesCVE-2002-2272Highorg.apache.tomcat:tomcat: Apache Tomcat DoS via Malicious Get RequestCVE-2002-2008Mediumorg.apache.tomcat:tomcat: Apache Tomcat Leaks Information via Error MessageCVE-2002-2009Mediumorg.apache.tomcat:tomcat: Apache Tomcat Leaks Pathname Information via Error MessageCVE-2002-2006Loworg.apache.tomcat:tomcat: Apache Tomcat Default Installation Reveals Sensitive InformationCVE-2002-1567Mediumorg.apache.tomcat:tomcat: Apache Tomcat XSS VulnerabilityCVE-2002-1533Mediumorg.mortbay.jetty:jetty: Jetty Javascript Inclusion VulnerabilityCVE-2002-1394Highorg.apache.tomcat:tomcat: Apache Tomcat Source Code DisclosureCVE-2002-1148Mediumorg.apache.tomcat:tomcat: Apache Tomcat Source Code DisclosureCVE-2002-0935Mediumorg.apache.tomcat:tomcat: Apache Tomcat DoS Via Requests Including Null CharactersCVE-2002-0493Highorg.apache.tomcat:tomcat: Apache Tomcat may be started without proper security settingsCVE-2001-0917Mediumorg.apache.tomcat:tomcat: Apache Tomcat Reveals Path through Long URLCVE-2001-0829Mediumorg.apache.tomcat:tomcat: Apache Tomcat allows webmasters to insert xss into error messagesCVE-2001-0590Mediumorg.apache.tomcat:tomcat-servlet-api: Apache Tomcat Allows Source DisclosureCVE-2000-1210Mediumorg.apache.tomcat:tomcat: Apache Tomcat Directory Traversal

Stop the waste.
Protect your environment with Kodem.