Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-9480Criticalorg.apache.spark:spark-parent_2.11: Improper Authentication in Apache SparkCVE-2019-14900Mediumorg.hibernate:hibernate-core: SQL Injection in Hibernate ORMCVE-2020-11980Mediumorg.apache.karaf.management:org.apache.karaf.management.server: Server-Side Request Forgery in KarafCVE-2020-13973Mediumcom.mikesamuel:json-sanitizer: Cross-site scripting in json-sanitizerCVE-2018-21234Criticalorg.jodd:jodd-json: Deserialization of Untrusted Data in JoddCVE-2021-31684Highnet.minidev:json-smart: Out of bounds read in json-smartCVE-2021-43841Mediumorg.xwiki.platform:xwiki-platform-oldcore: Cross-site Scripting by SVG upload in xwiki-platformCVE-2021-32732Highorg.xwiki.platform:xwiki-platform-administration-ui: Cross-Site Request Forgery in xwiki-platformCVE-2020-15813Highorg.graylog:graylog-parent: Improper Certificate Validation in GraylogCVE-2020-1948Criticalorg.apache.dubbo:dubbo: Deserialization of Untrusted Data in Apache DubboCVE-2020-1954Mediumorg.apache.cxf:cxf-rt-management: Apache CXF JMX Integration is vulnerable to a MITM attackCVE-2020-24164Highcom.taoensso:nippy: Gadget chain attack in NippyCVE-2019-12416Mediumorg.apache.deltaspike:deltaspike: Injection in DeltaSpikeCVE-2020-13928Mediumorg.apache.atlas:apache-atlas: Cross-site scripting in Apache AtlasCVE-2019-10091Highorg.apache.geode:geode-core: Apache Geode SSL endpoint verification vulnerabilityCVE-2020-10591Highcom.walmartlabs.concord:concord-common: Exposure of Sensitive Information to an Unauthorized Actor in ConcordCVE-2019-11343Criticalorg.torpedoquery:org.torpedoquery: Vulnerability in Torpedo QueryCVE-2020-15839Mediumcom.liferay.portal:release.dxp.bom: Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXPCVE-2020-1947Highorg.apache.shardingsphere:shardingsphere: Deserialization of Untrusted Data in Apache ShardingSphereCVE-2020-13951Highorg.apache.openmeetings:openmeetings-parent: Denial of service in Apache OpenMeetingsCVE-2020-13953Mediumorg.apache.tapestry:tapestry-core: Improper file downloads in Apache TapestryCVE-2020-2287Mediumorg.jenkins-ci.plugins:audit-trail: Request logging bypass in Jenkins Audit Trail PluginCVE-2019-17640Criticalio.vertx:vertx-web: Path Traversal in Eclipse VertCVE-2018-11764Highorg.apache.hadoop:hadoop-main: Authentication bypass in Apache HadoopCVE-2020-13937Mediumorg.apache.kylin:kylin: Authentication bypass in Apache Kylin

Stop the waste.
Protect your environment with Kodem.