Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-0758Mediumde.ipb-halle:molecularfaces: JavaScript execution via malicious molfiles (XSS)CVE-2021-20289Mediumorg.jboss.resteasy:resteasy-core: Exposure of class information in RESTEasyCVE-2021-28163Loworg.eclipse.jetty:jetty-deploy: Directory exposure in jettyCVE-2021-28165Highorg.eclipse.jetty:jetty-server: Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resourcesCVE-2021-28164Mediumorg.eclipse.jetty:jetty-webapp: Authorization Before Parsing and Canonicalization in jettyCVE-2024-23688Lowtech.pegasys.discovery:discovery: Discovery uses the same AES/GCM Nonce throughout the sessionCVE-2021-28100Mediumcom.netflix.priam:priam: Netflix/Priam: Temporary Directory Information DisclosureCVE-2021-21409Mediumio.netty:netty-codec-http2: Possible request smuggling in HTTP/2 due missing validation of content-lengthCVE-2021-28099Mediumcom.netflix.hollow:hollow: Insecure temporary file in Netflix OSS HollowCVE-2020-8908Lowcom.google.guava:guava: Information Disclosure in GuavaCVE-2021-21380Highorg.xwiki.platform:xwiki-platform-ratings-api: Rating Script Service expose XWiki to SQL injectionCVE-2021-21379Loworg.xwiki.platform:xwiki-platform-rendering-wikimacro-store: It's possible to execute anything with the rights of the author of a macro which uses the {{wikimacrocontent}} macroCVE-2021-21351Mediumcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-21350Mediumcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-21349Mediumcom.thoughtworks.xstream:xstream: A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a…CVE-2021-21348Mediumcom.thoughtworks.xstream:xstream: XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)CVE-2021-21347Mediumcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-21346Mediumcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-21345Mediumcom.thoughtworks.xstream:xstream: XStream is vulnerable to a Remote Command Execution attackCVE-2021-21344Mediumcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary Code Execution attackCVE-2021-21343Mediumcom.thoughtworks.xstream:xstream: XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient…CVE-2021-21342Mediumcom.thoughtworks.xstream:xstream: A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a…CVE-2021-21341Highcom.thoughtworks.xstream:xstream: XStream can cause a Denial of Service.CVE-2021-25329Highorg.apache.tomcat.embed:tomcat-embed-core: Potential remote code execution in Apache TomcatCVE-2021-22132Mediumorg.elasticsearch:elasticsearch: Insufficiently Protected Credentials in Elasticsearch

Stop the waste.
Protect your environment with Kodem.