Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-20222Highorg.keycloak:keycloak-parent: Code injection in keycloakCVE-2021-21430Mediumorg.openapitools:openapi-generator: Creation of Temporary File in Directory with Insecure Permissions in auto-generated Java, Scala codeCVE-2021-21428Criticalorg.openapitools:openapi-generator-online: Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generatorCVE-2020-7709Mediumjson-pointer: Prototype pollution in json-pointerCVE-2021-28657Mediumorg.apache.tika:tika: Infinite loop in Apache TikaCVE-2021-22112Highorg.springframework.security:spring-security-web: Privilege escalation in spring securityCVE-2021-26074Mediumcom.atlassian.connect:atlassian-connect-spring-boot-starter: Broken Authentication in Atlassian Connect Spring BootCVE-2021-22113Mediumorg.springframework.cloud:spring-cloud-netflix-zuul: Incorrect Authorization in Spring Cloud Netflix ZuulCVE-2021-29262Highorg.apache.solr:solr-core: Improper permission handling in Apache SolrCVE-2021-27905Highorg.apache.solr:solr-parent: Server-Side Request Forgery in Apache SolrCVE-2021-29943Criticalorg.apache.solr:solr-parent: Incorrect Authorization in Apache SolrCVE-2021-23339Mediumcom.typesafe.akka:akka-http-core: HTTP Request Smuggling in akka-http-coreCVE-2020-10544Mediumprimefaces: Cross-site Scripting in PrimeFacesCVE-2020-24554Highcom.liferay.portal:release.portal.bom: Open Redirect in Liferay PortalCVE-2020-13946Mediumorg.apache.cassandra:cassandra-all: Man-in-the-middle attack in Apache CassandraCVE-2020-25020Criticalnet.sf.mpxj:mpxj: Improper Restriction of XML External Entity Reference in MPXJCVE-2020-9298Highcom.netflix.spinnaker.orca:orca-core: Server-Side Request Forgery in Spinnaker OrcaCVE-2020-13933Highorg.apache.shiro:shiro-core: Authentication bypass in Apache ShiroCVE-2020-11976Highorg.apache.wicket:wicket-core: Exposure of Sensitive Information to an Unauthorized Actor in Apache WicketCVE-2020-1951Mediumorg.apache.tika:tika: Infinite Loop in Apache TikaCVE-2020-1950Mediumorg.apache.tika:tika: Uncontrolled Resource Consumption in Apache TikaCVE-2020-9489Mediumorg.apache.tika:tika: Missing Release of Memory after Effective Lifetime in Apache TikaCVE-2020-13921Criticalorg.apache.skywalking:oap-server: SQL Injection in Apache SkyWalkingCVE-2020-1957Criticalorg.apache.shiro:shiro-core: Improper Authentication in Apache ShiroCVE-2020-11989Criticalorg.apache.shiro:shiro-core: Improper Authentication in Apache Shiro

Stop the waste.
Protect your environment with Kodem.