Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-28452Highcom.softwaremill.akka-http-session:core_2.12: Cross-Site Request Forgery in com.softwaremill.akka-http-session:core_2.12CVE-2020-1952Highorg.apache.iotdb:iotdb-parent: Improper Certificate Validation in Apache IoTDBCVE-2020-1964Highorg.apache.heron:heron-simulator: Deserialization of Untrusted Data in Apache HeronCVE-2019-17557Loworg.apache.syncope.client:syncope-client-enduser: Cross-site scripting in Apache Syncome EndUserCVE-2021-21667Mediumorg.jenkins-ci.plugins:scriptler: Stored XSS vulnerability in Jenkins Scriptler PluginCVE-2021-21668Mediumorg.jenkins-ci.plugins:scriptler: Stored XSS vulnerability in Jenkins Scriptler PluginCVE-2021-29061Highcom.github.fracpete:vfsjfilechooser2: ReDOS in Vfsjfilechooser2CVE-2021-30468Highorg.apache.cxf:apache-cxf: Infinite loop in Apache CFXCVE-2021-4133Highorg.keycloak:keycloak-services: Improper Authorization in KeycloakGHSA-3QPM-H9CH-PX3CCriticalorg.powernukkit:powernukkit: Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j libraryCVE-2021-44145Mediumorg.apache.nifi:nifi: Exposure of Sensitive Information to an Unauthorized Actor in Apache NiFiCVE-2021-44832Mediumorg.apache.logging.log4j:log4j-core: Improper Input Validation and Injection in Apache Log4j2CVE-2021-45105Highorg.apache.logging.log4j:log4j-core: Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled RecursionGHSA-3W6P-8F82-GW8RHighru.yandex.clickhouse:clickhouse-jdbc-bridge: Using JMSAppender in log4j configuration may lead to deserialization of untrusted dataCVE-2020-35215Mediumio.atomix:atomix: Malicious Atomix node queries expose sensitive informationCVE-2020-35209Highio.atomix:atomix: An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information.CVE-2020-35214Highio.atomix:atomix: An issue in Atomix v3.1.5 allows a malicious Atomix node to remove states of ONOS storage via abuse of primitive operations.CVE-2020-35210Mediumio.atomix:atomix: A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack using Raft…CVE-2020-35216Mediumio.atomix:atomix: An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.CVE-2020-35213Highio.atomix:atomix: An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.CVE-2020-35211Highio.atomix:atomix: An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node.CVE-2021-42550Mediumch.qos.logback:logback-core: Deserialization of Untrusted Data in logbackGHSA-J7C3-96RF-JRRPCriticalde.averbis.textanalysis:pear-archetype: Critical vulnerability in log4j may affect generated PEAR projectsGHSA-HWVM-VFW8-93MWMediumorg.odpi.egeria:egeria-connector-xtdb: Vulnerable dependency in XTDB connectorCVE-2021-23264Criticalorg.craftercms:crafter-search: Exposure of Resource to Wrong Sphere in org.craftercms:crafter-search

Stop the waste.
Protect your environment with Kodem.