Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-3312Mediumorg.opencms:opencms-core: XML External Entity Reference in org.opencms:opencms-coreCVE-2020-29204Mediumcom.xuxueli:xxl-job-core: Cross-site Scripting in XXL-JOBCVE-2020-8897Highcom.amazonaws:aws-encryption-sdk-java: Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustnessCVE-2021-28170Mediumcom.sun.el:el-ri: Improper Input Validation in Jakarta Expression LanguageCVE-2021-41862Criticalcom.googlecode.aviator:aviator: Expression injection in AviatorScriptCVE-2021-41616Criticalorg.apache.ddlutils:ddlutils: Deserialization of Untrusted Data in org.apache.ddlutils:ddlutilsCVE-2021-25959Mediumorg.opencrx:opencrx-core: Cross-site Scripting in OpenCRXCVE-2020-7692Highcom.google.oauth-client:google-oauth-client: Improper Authorization in Google OAuth ClientCVE-2021-36749Mediumorg.apache.druid:druid-core: Druid ingestion system Authenticated users can read data from other sources than intended CVE-2021-38153Mediumorg.apache.kafka:kafka_2.11: Observable Discrepancy in Apache KafkaCVE-2021-41084Highorg.http4s:http4s-client_2.12: Response Splitting from unsanitized headersCVE-2021-40690Highorg.apache.santuario:xmlsec: Exposure of Sensitive Information to an Unauthorized Actor in Apache SantuarioCVE-2021-41079Highorg.apache.tomcat:tomcat: Infinite loop in Tomcat due to parsing errorCVE-2020-21122Highcom.bstek.ureport:ureport2-console: Server-Side Request Forgery in UReportCVE-2020-21125Criticalcom.bstek.ureport:ureport2-core: Remote code execution in UReportCVE-2020-1744Mediumorg.keycloak:keycloak-core: Exposure of Sensitive Information in keycloakCVE-2021-22147Mediumorg.elasticsearch:elasticsearch: Exposure of sensitive information in ElasticsearchCVE-2021-39239Highorg.apache.jena:jena-core: XML External Entity Reference in Apache JenaCVE-2021-41303Criticalorg.apache.shiro:shiro-core: Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypassCVE-2021-40146Criticalorg.apache.any23:apache-any23: Remote Code Execution in Any23CVE-2021-38555Criticalorg.apache.any23:apache-any23: XML Injection in Any23CVE-2021-37579Criticalorg.apache.dubbo:dubbo: Security check skip in Apache DubboCVE-2021-36161Criticalorg.apache.dubbo:dubbo: Remote Code Execution in Apache DubboCVE-2021-37137Highio.netty:netty-codec: SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary wayCVE-2021-37136Highio.netty:netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data

Stop the waste.
Protect your environment with Kodem.