Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-36162Highorg.apache.dubbo:dubbo: Remote Code Execution in Apache DubboCVE-2021-36163Criticalorg.apache.dubbo:dubbo: Hessian protocol configuration vulnerability in Apache DubboCVE-2021-40143Highorg.sonatype.nexus:nexus-repository: HTTP header injection in Sonatype Nexus RepositoryCVE-2021-39194Mediumcom.charleskorn.kaml:kaml: Improper Handling of Missing Values in kamlCVE-2021-39177Highorg.geysermc:connector: User impersonation due to incorrect handling of the login JWTCVE-2020-13929Highorg.apache.zeppelin:zeppelin: Authentication bypass in Apache ZeppelinCVE-2019-10095Criticalorg.apache.zeppelin:zeppelin: Bash command injection in Apache ZeppelinCVE-2021-27578Mediumorg.apache.zeppelin:zeppelin: Cross-site Scripting in Apache ZeppelinCVE-2021-39185Criticalorg.http4s:http4s-server_2.13.0-M5: Default CORS config allows any origin with credentialsCVE-2021-34371Criticalorg.neo4j:neo4j: Deserialization of Untrusted Data in Neo4jCVE-2021-39132Mediumorg.rundeck:rundeck-core: YAML deserialization can run untrusted codeCVE-2021-39133Highorg.rundeck:rundeck-core: Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck serverCVE-2020-6950Highorg.glassfish:mojarra-parent: Directory traversal in Eclipse MojarraCVE-2021-32827Mediumorg.mock-server:mockserver: Injection in MockServerGHSA-HW7R-QRHP-5PFFMediumcom.vaadin:vaadin-bom: Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20CVE-2021-33605Mediumcom.vaadin:vaadin-checkbox-flow: Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20CVE-2021-39139Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-39140Mediumcom.thoughtworks.xstream:xstream: XStream can cause a Denial of ServiceCVE-2021-39141Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-39144Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to a Remote Command Execution attackCVE-2021-39145Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-39146Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-39147Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-39148Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-39149Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attack

Stop the waste.
Protect your environment with Kodem.