Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-24721Highorg.cometd.java:cometd-java-oort: Improper Authorization in org.cometd.oortCVE-2020-36518Highcom.fasterxml.jackson.core:jackson-databind: Deeply nested json in jackson-databindCVE-2018-25031Mediumswagger-ui: Spoofing attack in swagger-uiCVE-2021-44667Mediumcom.alibaba.nacos:nacos-common: Cross-site Scripting in NacosCVE-2021-38296Highorg.apache.spark:spark-core: Authentication Bypass by Capture-replay in Apache SparkCVE-2022-26520Loworg.postgresql:postgresql: Path traversal in org.postgresql:postgresqlCVE-2021-44585Mediumorg.jeecgframework.boot:jeecg-boot-base: Cross-site Scripting in jeecg-bootCVE-2022-25312Criticalorg.apache.any23:apache-any23: Improper Restriction of XML External Entity Reference in Any23CVE-2022-0839Criticalorg.liquibase:liquibase-core: Improper Restriction of XML External Entity Reference in LiquibaseCVE-2022-26336Mediumorg.apache.poi:poi-scratchpad: Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpadCVE-2021-46384Criticalnet.mingsoft:ms-mcms: Remote code execution in net.mingsoft:ms-mcmsCVE-2021-38266Highcom.liferay:com.liferay.portal.security.ldap.impl: Liferay Portal and Liferay DXP fails to properly import users from LDAPCVE-2021-38263Mediumcom.liferay:com.liferay.server.admin.web: Liferay Portal and Liferay DXP cross-site scripting (XSS) vulnerability via the script consoleCVE-2021-38267Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in edit blog entry pageCVE-2021-38269Mediumcom.liferay:com.liferay.gogo.shell.web: Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in the Gogo Shell moduleCVE-2021-38265Mediumcom.liferay:com.liferay.layout.admin.web: Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS)CVE-2021-38264Mediumcom.liferay:com.liferay.frontend.taglib.clay: Liferay Portal vulnerable to cross-site scripting (XSS) via the keywords parameterCVE-2022-25146Mediumcom.liferay:com.liferay.remote.app.web: Liferay Portal and Liferay DXP fails to check origin of event messagesCVE-2022-23899Criticalnet.mingsoft:ms-mcms: SQL injection in net.mingsoft:ms-mcmsCVE-2022-23898Criticalnet.mingsoft:ms-mcms: SQL injection in net.mingsoft:ms-mcmsCVE-2022-23708Mediumorg.elasticsearch:elasticsearch: Elasticsearch privilege escalationCVE-2022-0265Criticalcom.hazelcast:hazelcast: XML External Entity Reference in HazelcastCVE-2022-22947Criticalorg.springframework.cloud:spring-cloud-gateway: Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecuredCVE-2021-38268Mediumcom.liferay:com.liferay.dynamic.data.mapping.service: Liferay Portal and Liferay DXP has incorrect default permissions for site membersCVE-2022-23640Criticalcom.monitorjbl:xlsx-streamer: Improper Restriction of XML External Entity Reference in com.monitorjbl:xlsx-streamer

Stop the waste.
Protect your environment with Kodem.