Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-46385Highnet.mingsoft:ms-mcms: Mingsoft MCMS SQL injection vulnerabilityCVE-2021-46089Criticalorg.jeecgframework.boot:jeecg-boot-base: SQL Injection in JeecgBootCVE-2022-22929Criticalnet.mingsoft:ms-mcms: Arbitrary File Upload in Mingsoft MCMSCVE-2022-22930Criticalnet.mingsoft:ms-mcms: RCE in Mingsoft MCMSCVE-2022-23315Criticalnet.mingsoft:ms-mcms: Arbitrary file upload in Mingsoft MCMSCVE-2021-42357Mediumorg.apache.knox:gateway-service-knoxsso: Cross-site Scripting in Apache Knox SSOCVE-2022-0239Criticaledu.stanford.nlp:stanford-corenlp: corenlp is vulnerable to Improper Restriction of XML External Entity ReferenceCVE-2024-23683Highde.tum.in.ase:artemis-java-test-sandbox: Trust Boundary Violation due to Incomplete Blacklist in Test Failure Processing in AresCVE-2022-23106Lowio.jenkins:configuration-as-code: Observable Discrepancy and Observable Timing Discrepancy in Jenkins Configuration as Code PluginCVE-2022-23107Highio.jenkins.plugins:warnings-ng: Path Traversal in Jenkins Warnings Next Generation PluginCVE-2022-20612Mediumorg.jenkins-ci.main:jenkins-core: Cross-Site Request Forgery in JenkinsCVE-2021-40525Criticalorg.apache.james:james-server: Path traversal in Apache JamesCVE-2022-23302Highlog4j:log4j: Deserialization of Untrusted Data in Log4j 1.xCVE-2022-23305Criticallog4j:log4j: SQL Injection in Log4j 1.2.xGHSA-V57X-GXFJ-484QCriticalcom.hazelcast.jet:hazelcast-jet: Security Advisory for "Log4Shell"CVE-2024-23684Highcom.upokecenter:cbor: Denial of service in CBOR libraryCVE-2022-21700Mediumio.micronaut:micronaut-http: Memory leak in micronaut-coreCVE-2022-23221Criticalcom.h2database:h2: Arbitrary code execution in H2 ConsoleCVE-2022-0219Mediumio.github.skylot:jadx-core: Improper Restriction of XML External Entity Reference in skylot/jadxCVE-2022-23435Highpl.droidsonroids.gif:android-gif-drawable: android-gif-drawable vulerable to denial of service due to unrestricted comment lengthCVE-2022-21363Mediummysql:mysql-connector-java: Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors JavaCVE-2022-23307Criticallog4j:log4j: Deserialization of Untrusted Data in Apache Log4jCVE-2022-0198Mediumedu.stanford.nlp:stanford-corenlp: XML External Entity Reference in edu.stanford.nlp:stanford-corenlpCVE-2022-20614Mediumorg.jenkins-ci.plugins:mailer: Incorrect Permission Assignment for Critical Resource in Jenkins Mailer PluginCVE-2022-20613Mediumorg.jenkins-ci.plugins:mailer: Cross-Site Request Forgery in Jenkins Mailer Plugin

Stop the waste.
Protect your environment with Kodem.