Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-36186Highcom.fasterxml.jackson.core:jackson-databind: Unsafe Deserialization in jackson-databindCVE-2021-37580Criticalorg.apache.shenyu:shenyu-admin: Improper Authentication in Apache ShenYu AdminCVE-2021-41269Criticalcom.cronutils:cron-utils: Critical vulnerability found in cron-utilsCVE-2021-43570Criticalcom.starkbank.ellipticcurve:starkbank-ecdsa: Improper Verification of Cryptographic Signature in starkbank-ecdsaCVE-2021-43466Criticalorg.thymeleaf:thymeleaf-spring5: Template injection in thymeleaf-spring5CVE-2021-22051Mediumorg.springframework.cloud:spring-cloud-gateway: Request injection in Spring Cloud GatewayCVE-2020-14389Highorg.keycloak:keycloak-core: Improper privilege management in KeycloakGHSA-9WX7-JRVC-28MMHighstarkbank-ecdsa: Signature verification vulnerability in Stark Bank ecdsa librariesCVE-2021-33611Mediumcom.vaadin:vaadin-bom: Reflected cross-site scripting in vaadin-menu-bar webjar resources in Vaadin 14CVE-2021-41973Mediumorg.apache.mina:mina-core: Infinite loop in Apache MINACVE-2021-27644Highorg.apache.dolphinscheduler:dolphinscheduler-server: SQL injection in Apache DolphinScheduler CVE-2021-41189Highorg.dspace:dspace-api: Communities and collections administrators can escalate their privilege up to system administratorCVE-2021-40865Criticalorg.apache.storm:storm: Deserialization of Untrusted Data leading to Remote Code Execution in Apache StormCVE-2021-38294Criticalorg.apache.storm:storm: Command injection leading to Remote Code Execution in Apache StormCVE-2021-41183Mediumjquery-ui: XSS in `*Text` options of the Datepicker widget in jquery-uiCVE-2021-41184Mediumjquery-ui: XSS in the `of` option of the `.position()` util in jquery-uiCVE-2021-41182Mediumjquery-ui: XSS in the `altField` option of the Datepicker widget in jquery-uiCVE-2019-10170Highorg.keycloak:keycloak-core: Privilege Defined With Unsafe Actions in KeycloakCVE-2021-42575Criticalcom.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer: Policies not properly enforced in OWASP Java HTML SanitizerCVE-2021-42340Highorg.apache.tomcat:tomcat: Missing Release of Resource after Effective Lifetime in Apache TomcatGHSA-FR26-QJC8-MVJXMediumcom.vaadin:flow-server: Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19GHSA-JFMF-W293-8XR8Highcom.vaadin:vaadin-bom: Regular expression Denial of Service (ReDoS) in EmailValidator class in V7 compatibility module in Vaadin 8GHSA-J23J-Q57M-63V3Mediumcom.vaadin:vaadin-server: Denial of service in DataCommunicator class in Vaadin 8CVE-2021-33609Mediumcom.vaadin:vaadin-server: Denial of service in DataCommunicator class in Vaadin 8CVE-2021-25738Mediumio.kubernetes:client-java: Code injection in Kubernetes Java Client

Stop the waste.
Protect your environment with Kodem.