Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-13935Highorg.apache.tomcat:tomcat: Infinite Loop in Apache TomcatCVE-2020-13934Highorg.apache.tomcat:tomcat: Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache TomcatCVE-2022-22931Mediumorg.apache.james:james-server: Path Traversal in Apache James ServerCVE-2021-36152Criticalorg.apache.gobblin:gobblin-core: Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-ServiceCVE-2021-36151Mediumorg.apache.gobblin:gobblin-core: Hadoop token in temp file visible to all users in Apache GobblinCVE-2022-23913Highorg.apache.activemq:artemis-core-client: Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)CVE-2022-21724Highorg.postgresql:postgresql: pgjdbc Does Not Check Class Instantiation when providing Plugin ClassesCVE-2021-41571Mediumorg.apache.pulsar:pulsar: Improper Input Validation in Apache PulsarCVE-2022-24198Mediumcom.itextpdf:itext7-core: Out-of-bounds Read in iTextCVE-2022-24196Mediumcom.itextpdf:itext7-core: Allocation of Resources Without Limits or Throttling in iTextCVE-2022-24197Mediumcom.itextpdf:itext7-core: Out-of-bounds Write in iTextCVE-2021-42767Criticalorg.neo4j.procedure:apoc: Neo4j Graph Database vulnerable to Path TraversalCVE-2021-43859Highcom.thoughtworks.xstream:xstream: Denial of Service by injecting highly recursive collections or maps in XStreamCVE-2022-23596Highcom.github.junrar:junrar: Junrar vulnerable to infinite loop via extracting carefully crafted RAR archiveCVE-2022-23181Highorg.apache.tomcat:tomcat: Race condition in Apache TomcatCVE-2021-23460Highmin-dash: Prototype pollution in min-dashCVE-2022-22932Mediumorg.apache.karaf:apache-karaf: Path traversal in Apache KarafCVE-2021-41766Highorg.apache.karaf.management:org.apache.karaf.management.server: Insecure Java Deserialization in Apache KarafCVE-2022-23945Highorg.apache.shenyu:shenyu-common: Missing authentication in ShenYuCVE-2022-23223Highorg.apache.shenyu:shenyu-common: Password exposure in ShenYuCVE-2022-23944Criticalorg.apache.shenyu:shenyu-common: Missing authentication in ShenYuCVE-2021-45029Criticalorg.apache.shenyu:shenyu-common: Code injection in ShenYuCVE-2022-23437Mediumxerces:xercesImpl: Infinite Loop in Apache Xerces JavaCVE-2021-46383Highnet.mingsoft:ms-mcms: Mingsoft MCMS SQL injection vulnerabilityCVE-2021-46386Criticalnet.mingsoft:ms-mcms: Mingsoft MCMS vulnerable to Remote Code Execution via file upload.

Stop the waste.
Protect your environment with Kodem.