Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-13955Mediumorg.apache.calcite:calcite-core: Missing Authentication for Critical Function in Apache CalciteCVE-2020-17510Criticalorg.apache.shiro:shiro-spring: Authentication bypass in Apache ShiroCVE-2021-29459Criticalorg.xwiki.platform:xwiki-platform-oldcore: XSS Cross Site ScriptingGHSA-6HGR-2G6Q-3RMCMediumcom.vaadin:flow-client: Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19CVE-2021-31408Mediumcom.vaadin:vaadin-bom: Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19CVE-2021-29451Criticalcom.manydesigns:portofino-dispatcher: Missing validation of JWT signature in `ManyDesigns/Portofino`GHSA-CRH4-294P-VCFQHighcom.vaadin:vaadin-text-field-flow: Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17CVE-2018-25007Lowcom.vaadin:flow-server: Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11CVE-2019-25027Mediumcom.vaadin:flow-server: Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13CVE-2020-36319Lowcom.vaadin:flow-server: Potential sensitive data exposure in applications using Vaadin 15CVE-2020-36321Mediumcom.vaadin:flow-server: Directory traversal in development mode handler in Vaadin 14 and 15-17CVE-2021-31404Mediumcom.vaadin:flow-server: Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18CVE-2021-31403Mediumcom.vaadin:vaadin-bom: Timing side channel vulnerability in UIDL request handler in Vaadin 7 and 8CVE-2021-31407Highcom.vaadin:flow-server: OSGi applications using Vaadin 12-14 and 19 vulnerable to server classes and resources exposureCVE-2021-31406Mediumcom.vaadin:flow-server: Timing side channel vulnerability in endpoint request handler in Vaadin 15-19CVE-2019-25028Mediumcom.vaadin:vaadin-bom: Stored cross-site scripting in Grid component in Vaadin 7 and 8CVE-2020-36320Highcom.vaadin:vaadin-bom: Regular expression denial of service (ReDoS) in EmailValidator class in Vaadin 7GHSA-3H5R-928V-MXHHLowcom.vaadin:vaadin-bom: Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11GHSA-JQJ4-R483-4GVRMediumcom.vaadin:vaadin-bom: Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13GHSA-76F4-FW33-6J2VLowcom.vaadin:vaadin-bom: Potential sensitive data exposure in applications using Vaadin 15GHSA-82MF-MMH7-HXP5Mediumcom.vaadin:vaadin-bom: Directory traversal in development mode handler in Vaadin 14 and 15-17GHSA-C6C4-7X48-4CQPMediumcom.vaadin:vaadin-bom: Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18CVE-2021-31405Highcom.vaadin:vaadin-bom: Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17GHSA-9H6G-6MXG-VVP4Mediumcom.vaadin:vaadin-bom: Timing side channel vulnerability in endpoint request handler in Vaadin 15-19GHSA-J9WR-49VQ-RM5GHighcom.vaadin:vaadin-bom: Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19

Stop the waste.
Protect your environment with Kodem.