Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-25711Mediumorg.infinispan:infinispan-core: Improper Access Control in infinispan-server-runtimeCVE-2020-28923Lowcom.typesafe.play:play: Data Amplification in Play FrameworkCVE-2020-17530Criticalorg.apache.struts:struts2-core: Remote code execution in Apache StrutsCVE-2020-17531Criticalorg.apache.tapestry:tapestry-project: Serialization vulnerability in Apache TapestryCVE-2020-11974Criticalorg.apache.dolphinscheduler:dolphinscheduler: Remote code execution in DolphinSchedulerCVE-2020-13931Criticalorg.apache.tomee:apache-tomee: Remote code execution in Apache TomEECVE-2020-17533Highorg.apache.accumulo:accumulo-master: Improper privilege handling in Apache AccumuloCVE-2020-35774Mediumcom.twitter:twitter-server_2.12: TwitterServer Cross-site Scripting via /histograms endpointCVE-2019-10797Mediumorg.wso2.transport.http:org.wso2.transport.http.netty: HTTP Response Splitting in WSO2 transport-httpCVE-2020-13654Highorg.xwiki.platform:xwiki-platform-web: Improper escaping in XWiki PlatformCVE-2024-23682Highde.tum.in.ase:artemis-java-test-sandbox: Class Loading Vulnerability in ArtemisCVE-2020-17518Highorg.apache.flink:flink-runtime: Upload of file to arbitrary path in Apache FlinkCVE-2020-11995Criticalorg.apache.dubbo:dubbo-parent: Deserialization exploitation in Apache DubboCVE-2020-13922Highorg.apache.dolphinscheduler:dolphinscheduler-api: Incorrect Default Permissions in Apache DolphinSchedulerCVE-2020-17534Highorg.netbeans.html:pom: Improper synchronization in Apache Netbeans HTML/Java APICVE-2020-27219Mediumorg.eclipse.hawkbit:hawkbit-parent: Cross-site Scripting in Eclipse HawkbitCVE-2020-17532Highorg.apache.servicecomb:java-chassis: Arbitrary code execution in Apache ServiceComb java-chassisCVE-2020-23262Criticalnet.mingsoft:ms-mcms: SQL injection without credentials in ming-soft MCMSCVE-2020-9492Highorg.apache.hadoop:hadoop-common: Improper Privilege Management in Apache HadoopCVE-2020-5428Mediumorg.springframework.cloud:spring-cloud-task-dependencies: SQL Injection in Spring Cloud TaskCVE-2020-13920Mediumorg.apache.activemq:activemq-parent: Improper Authentication in Apache ActiveMQCVE-2020-11998Criticalorg.apache.activemq:activemq-parent: Remote code execution in Apache ActiveMQCVE-2020-13932Mediumorg.apache.activemq:apache-artemis: Cross-site Scripting (XSS) in Apache ActiveMQ ArtemisCVE-2020-1958Mediumorg.apache.druid:druid: Credentials bypass in Apache DruidCVE-2020-17523Criticalorg.apache.shiro:shiro-web: Authentication bypass in Apache Shiro

Stop the waste.
Protect your environment with Kodem.