Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-39150Highcom.thoughtworks.xstream:xstream: A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a…CVE-2021-39151Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-39152Highcom.thoughtworks.xstream:xstream: A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a…CVE-2021-39153Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-39154Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-37714Highorg.jsoup:jsoup: Uncaught Exception in jsoupCVE-2020-15522Mediumorg.bouncycastle:bc-fips: Timing based private key exposure in Bouncy CastleCVE-2010-3300Mediumorg.owasp.esapi:esapi: Padding oracle attacksCVE-2021-33348Mediumcom.jfinal:jfinal: Cross-site scripting in jfinalGHSA-7QFM-6M33-RGG9Highcom.epam.reportportal:service-api: XML External Entity ReferenceCVE-2021-26920Mediumorg.apache.druid:druid-core: Druid ingestion system Authenticated users can read data from other sources than intendedCVE-2021-33192Mediumorg.apache.jena:jena-fuseki: Cross-site scripting in Apache Jena FusekiCVE-2021-30640Mediumorg.apache.tomcat:tomcat: Authentication Bypass by Alternate Name in Apache TomcatCVE-2021-33037Mediumorg.apache.tomcat:tomcat: HTTP Request Smuggling in Apache TomcatCVE-2021-30639Highorg.apache.tomcat:tomcat: Improper Handling of Exceptional Conditions in Apache TomcatCVE-2021-37578Criticalorg.apache.juddi:juddi-core: Deserialization of Untrusted Data in Apache jUDDICVE-2021-22144Mediumorg.elasticsearch:elasticsearch: Denial of Service in ElasticsearchCVE-2021-33900Highorg.apache.directory.studio:org.apache.directory.studio.parent: Missing encryption in Apache Directory StudioCVE-2020-35476Criticalnet.opentsdb:opentsdb: OS Command Injection in OpenTSDBCVE-2021-23408Mediumcom.graphhopper:graphhopper-web-bundle: Prototype Pollution in GraphHopperCVE-2021-35043Mediumorg.owasp.antisamy:antisamy: Cross-site Scripting in OWASP AntiSamyCVE-2021-36374Mediumorg.apache.ant:ant: Improper Handling of Length Parameter Inconsistency in Apache AntCVE-2021-36373Mediumorg.apache.ant:ant: Improper Handling of Length Parameter Inconsistency in Apache AntCVE-2021-36090Highorg.apache.commons:commons-compress: Improper Handling of Length Parameter Inconsistency in CompressCVE-2021-35517Highorg.apache.commons:commons-compress: Improper Handling of Length Parameter Inconsistency in Compress

Stop the waste.
Protect your environment with Kodem.