Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-13956Mediumorg.apache.httpcomponents:httpclient: Cross-site scripting in Apache HttpClientCVE-2017-1000486Criticalorg.primefaces:primefaces: Inadequate Encryption StrengthCVE-2021-22160Criticalorg.apache.pulsar:pulsar: Improper Verification of Cryptographic Signature in Apache Pulsar in TensorFlowCVE-2024-23680Mediumcom.amazonaws:aws-encryption-sdk-java: Improper Verification of Cryptographic Signature in aws-encryption-sdk-javaCVE-2021-32643Mediumorg.http4s:http4s-core: StaticFile.fromUrl can leak presence of a directoryCVE-2021-25933Mediumorg.opennms:opennms: Cross-site Scripting in OpenNMS HorizonCVE-2021-25929Mediumorg.opennms:opennms: Cross-site Scripting in OpenNMS HorizonCVE-2021-25931Highorg.opennms:opennms: Cross-Site Request Forgery in OpenNMS HorizonCVE-2021-25930Mediumorg.opennms:opennms: Cross-Site Request Forgery in OpenNMS HorizonCVE-2021-3536Loworg.wildfly:wildfly-parent: Cross-site Scripting in WildflyCVE-2020-11972Highorg.apache.camel:camel-rabbitmq: Deserialization of Untrusted Data in Apache Camel RabbitMQCVE-2020-1960Mediumorg.apache.flink:flink-core: Command injection in Apache FlinkCVE-2020-11971Highorg.apache.camel:camel: Improper Input Validation in Apache CamelCVE-2021-29506Mediumcom.graphhopper:graphhopper-nav: Navigate endpoint is vulnerable to regex injection that may lead to Denial of Service.CVE-2021-29505Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to a Remote Command Execution attackCVE-2021-32620Highorg.xwiki.commons:xwiki-commons-core: XWiki users registered with email verification can self re-activate their disabled accountsCVE-2021-32621Highorg.xwiki.commons:xwiki-commons-core: Script injection without script or programming rights through Gadget titlesCVE-2021-23900Highcom.mikesamuel:json-sanitizer: Uncaught Exception leading to Denial of Service in json-sanitizerCVE-2021-27582Criticalorg.mitre:openid-connect-parent: Autobinding vulnerability in MITREid ConnectCVE-2021-21043Mediumcom.adobe.acs:acs-aem-commons: Reflected Cross-site Scripting (XSS) in ACS CommonsCVE-2021-22696Highorg.apache.cxf:cxf: Authorization service vulnerable to DDos attacks in Apache CFXCVE-2021-26715Highorg.mitre:openid-connect-server: Server Side Request Forgery (SSRF) in org.mitre:openid-connect-serverCVE-2021-26544Mediumorg.apache.livy:livy-server: Apache Livy Cross-site scripting (XSS) in session namesCVE-2021-27906Mediumorg.apache.pdfbox:pdfbox: Uncontrolled Memory Allocation in Apache PDFBoxCVE-2021-24122Mediumorg.apache.tomcat.embed:tomcat-embed-core: Information Disclosure in Apache Tomcat

Stop the waste.
Protect your environment with Kodem.