Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2012-1094Highorg.jboss.as:jboss-as-server: JBoss AS may expose root content if excluded-contexts list is mismatchedCVE-2012-1592Highorg.apache.struts:struts2-core: Unrestricted Upload of File with Dangerous Type in Apache Struts2CVE-2012-4441Mediumorg.jenkins-ci.plugins:ci-game: Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)CVE-2012-4438Highorg.jenkins-ci.main:jenkins-core: Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP AccessCVE-2012-4439Mediumorg.jenkins-ci.main:jenkins-core: Jenkins allows Cross-Site Scripting (XSS) via Crafted URLCVE-2012-4440Mediumorg.jenkins-ci.plugins:violations: Jenkins Violation Plugin allows Cross-Site Scripting (XSS)CVE-2012-2945Highorg.apache.hadoop:hadoop-main: Hadoop symlink vulnerabilityCVE-2022-28367Mediumorg.owasp.antisamy:antisamy: Cross-site Scripting in OWASP AntiSamyCVE-2022-29577Mediumorg.owasp.antisamy:antisamy: Cross-site Scripting in OWASP AntiSamyCVE-2022-28366Highnet.sourceforge.htmlunit:neko-htmlunit: Denial of service in HtmlUnit-NekoCVE-2022-27340Highnet.mingsoft:ms-mcms: Cross Site Request Forgery in Mingsoft MCMSCVE-2022-24847Highorg.geoserver:gs-main: Improper Input Validation in GeoServerCVE-2011-2487Mediumorg.apache.ws.security:wss4j: Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4JCVE-2011-3923Criticalorg.apache.struts:struts2-core: Struts ParameterInterceptor vulnerability allows remote command executionCVE-2022-0272Highio.gitlab.arturbosch.detekt:detekt-core: XML External Entity Reference in detektCVE-2022-22969Mediumorg.springframework.security.oauth:spring-security-oauth2: Denial of service in Spring Security OAuth2CVE-2022-28108Highorg.seleniumhq.selenium:selenium-grid: Selenium Server (Grid) CSRFCVE-2022-26595Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP fails to check permissions to view sites/groupsCVE-2022-26593Mediumcom.liferay:com.liferay.asset.taglib: Liferay Portal and Liferay DXP allows arbitrary injection via the name of an asset categoryCVE-2021-3503Mediumorg.wildfly:wildfly-metrics: Metrics exposure in WildflyCVE-2022-26594Mediumcom.liferay:com.liferay.dynamic.data.mapping.form.field.type: Liferay Portal and Liferay DXP allows arbitrary injection via form fieldCVE-2022-22968Highorg.springframework:spring-context: Improper handling of case sensitivity in Spring FrameworkCVE-2021-31805Criticalorg.apache.struts:struts2-core: Expression Language Injection in Apache StrutsCVE-2022-29039Highcom.sonyericsson.hudson.plugins.gerrit:gerrit-trigger: Stored Cross-site Scripting vulnerability in Jenkins Gerrit Trigger PluginCVE-2022-29038Mediumorg.jenkins-ci.plugins:extended-choice-parameter: Stored Cross-site Scripting vulnerabilities in Jenkins Extended Choice Parameter Plugin

Stop the waste.
Protect your environment with Kodem.