Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-41193Highcom.wire:avs: Use of Externally-Controlled Format String in wire-avsCVE-2022-24947Highorg.apache.jspwiki:jspwiki-main: Cross Site Request Forgery in Apache JSPWikiCVE-2022-24948Mediumorg.apache.jspwiki:jspwiki-main: Cross-site Scripting in Apache JSPWikiCVE-2022-24329Mediumorg.jetbrains.kotlin:kotlin-stdlib: Improper Locking in JetBrains KotlinCVE-2021-44550Criticaledu.stanford.nlp:stanford-corenlp: Access Control vulnerability within CoreNLPCVE-2022-24613Mediumcom.drewnoakes:metadata-extractor: Improper Handling of Exceptional Conditions inn metadata-extractorCVE-2022-24614Highcom.drewnoakes:metadata-extractor: Allocation of Resources Without Limits or Throttling in metadata-extractorCVE-2022-24615Mediumnet.lingala.zip4j:zip4j: Uncaught Exception in zip4jCVE-2022-23848Criticalorg.alluxio:alluxio-core-common: Command injection in AlluxioCVE-2022-0672Mediumorg.eclipse.lemminx:lemminx-parent: Exposure of Sensitive Information to an Unauthorized Actor in LemMinXCVE-2022-0671Criticalorg.eclipse.lemminx:lemminx-parent: Server-Side Request Forgery and Uncontrolled Resource Consumption in LemMinXCVE-2022-0673Mediumorg.eclipse.lemminx:lemminx-parent: Path Traversal in LemMinXCVE-2021-46036Criticalnet.mingsoft:ms-mcms: File upload leading to RCE in MCMSCVE-2021-46037Highnet.mingsoft:ms-mcms: Path traversal in MCMSCVE-2021-46062Highnet.mingsoft:ms-basic: MCMS Arbitrary File Deletion vulnerabilityCVE-2021-46063Criticalnet.mingsoft:ms-mcms: Server Side Template Injection in MCMSCVE-2021-44868Criticalnet.mingsoft:ms-mcms: SQL injection in MCMSCVE-2022-22880Criticalorg.jeecgframework.boot:jeecg-boot-base: SQL Injection in Jeecg-bootCVE-2022-22885Criticalcn.hutool:hutool-http: Improper Certificate Validation in HutoolCVE-2022-22881Criticalorg.jeecgframework.boot:jeecg-boot-base: SQL Injection in Jeecg-bootGHSA-673J-QM5F-XPV8Mediumorg.postgresql:postgresql: pgjdbc Arbitrary File Write VulnerabilityCVE-2022-25173Highorg.jenkins-ci.plugins.workflow:workflow-cps: Improper Neutralization of Special Elements used in an OS Command in Jenkins Pipeline: Groovy PluginCVE-2022-25175Highorg.jenkins-ci.plugins.workflow:workflow-multibranch: Jenkins Pipeline: Multibranch Plugin vulnerable to OS Command InjectionCVE-2022-25174Highorg.jenkins-ci.plugins.workflow:workflow-cps-global-lib: Improper Neutralization of Special Elements used in an OS Command in Jenkins Pipeline: Shared Groovy Libraries PluginCVE-2022-25177Mediumorg.jenkins-ci.plugins.workflow:workflow-cps-global-lib: Improper Link Resolution Before File Access in Jenkins Pipeline: Shared Groovy Libraries Plugin

Stop the waste.
Protect your environment with Kodem.