Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-23463Highcom.h2database:h2: Improper Restriction of XML External Entity Reference in com.h2database:h2.CVE-2021-44549Highorg.apache.sling:org.apache.sling.commons.messaging.mail: Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Apache Sling Commons Messaging MailCVE-2021-43113Criticalcom.itextpdf:itext7-core: Command injection in itext7-coreGHSA-94G7-HPV8-H9QMCriticalcom.splunk.logging:splunk-library-javalogging: Remote code injection in Log4jCVE-2021-43821Criticalorg.opencastproject:opencast-ingest-service-impl: Files Accessible to External Parties in OpencastCVE-2018-16153Highorg.opencastproject:opencast-common: Opencast publishes global system account credentialsCVE-2021-43807Highorg.opencastproject:opencast-common: HTTP Method SpoofingGHSA-MF4F-J588-5XM8Criticalorg.opencastproject:opencast-common: Apache Log4j Remote Code ExecutionCVE-2021-4104Highlog4j:log4j: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted dataCVE-2021-45046Criticalorg.apache.logging.log4j:log4j-core: Incomplete fix for Apache Log4j vulnerabilityCVE-2021-42567Mediumorg.apereo.cas:cas-server-core-web: Cross-site Scripting in Apereo CASGHSA-XXFH-X98P-J8FRCriticalorg.ops4j.pax.logging:pax-logging-log4j2: Remote code injection in Log4j (through pax-logging-log4j2)CVE-2020-1940Highorg.apache.jackrabbit:oak-core: Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit OakCVE-2020-36282Highcom.rabbitmq.jms:rabbitmq-jms: Unsafe Deserialization that can Result in Code ExecutionCVE-2021-44228Criticalorg.apache.logging.log4j:log4j-core: Remote code injection in Log4jCVE-2020-28491Highcom.fasterxml.jackson.dataformat:jackson-dataformat-cbor: Denial of Service (DoS) in Jackson Dataformat CBORCVE-2020-36189Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2020-36187Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2020-36188Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2020-36183Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2020-36184Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2020-36180Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2020-36181Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2020-36185Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2020-36179Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databind

Stop the waste.
Protect your environment with Kodem.