Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-12642Highcom.epam.reportportal:service-api: XXE vulnerability in Launch importCVE-2021-29620Highcom.epam.reportportal:service-api: XXE vulnerability on Launch import with externally-defined DTD fileCVE-2021-34428Loworg.eclipse.jetty:jetty-server: SessionListener can prevent a session from being invalidated breaking logoutCVE-2021-32623Highorg.opencastproject:opencast-kernel: Billion laughs attack (XML bomb)CVE-2021-27568Mediumnet.minidev:json-smart: Improper Check for Unusual or Exceptional Conditions in json-smartCVE-2021-27807Mediumorg.apache.pdfbox:pdfbox: Excessive Iteration Denial of Service in Apache PDFBoxCVE-2021-23331Lowcom.squareup:connect: Insecure temporary file used in com.squareup:connectCVE-2021-26919Highorg.apache.druid:druid: Arbitrary code execution in Apache DruidCVE-2021-20220Mediumio.undertow:undertow-core: HTTP request smuggling in UndertowCVE-2021-25122Highorg.apache.tomcat.embed:tomcat-embed-core: Exposure of Sensitive Information to an Unauthorized Actor in Apache TomcatCVE-2021-27576Highorg.apache.openmeetings:openmeetings-parent: Uncontrolled Resource Consumption in Apache OpenMeetings serverCVE-2021-25646Highorg.apache.druid:druid: Code injection in Apache DruidCVE-2021-26117Highorg.apache.activemq:activemq-parent: Improper Authentication in Apache ActiveMQ and Apache ArtemisCVE-2021-26118Highorg.apache.activemq:artemis-openwire-protocol: Apache ActiveMQ Artemis vulnerable to Improper Access ControlCVE-2021-23926Criticalorg.apache.xmlbeans:xmlbeans: Improper Restriction of Recursive Entity References in Apache XMLBeansCVE-2021-23899Criticalcom.mikesamuel:json-sanitizer: Arbitrary code injection in json-sanitizerCVE-2021-27850Criticalorg.apache.tapestry:tapestry-core: Remote code execution in Apache TapestryCVE-2021-26291Criticalorg.apache.maven:maven-compat: Origin Validation Error in Apache MavenCVE-2021-26296Highorg.apache.myfaces.core:myfaces-core-module: Cryptographically weak CSRF tokens in Apache MyFacesCVE-2021-21620Mediumorg.jenkins-ci.plugins:claim: Cross-Site Request Forgery in the Jenkins Claim pluginCVE-2021-21654Mediumorg.jenkins-ci.plugins:p4: Missing Authorization in Jenkins P4 pluginCVE-2021-21653Mediumorg.jenkins-ci.plugins:xray-connector: Missing Authorization in jenkins xray-connectorCVE-2021-21651Mediumorg.jenkins-ci.plugins:s3: Missing Authorization in Jenkins S3 publisher PluginCVE-2021-21650Mediumorg.jenkins-ci.plugins:s3: Missing Authorization in Jenkins S3 publisher PluginCVE-2021-21652Highorg.jenkins-ci.plugins:xray-connector: CSRF vulnerability in Jenkins Xray - Test Management for Jira Plugin allows capturing credentials

Stop the waste.
Protect your environment with Kodem.