Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-7014Mediumorg.elasticsearch:elasticsearch: Privilege Escalation Flaw in ElasticsearchCVE-2020-7020Loworg.elasticsearch:elasticsearch: Privilege Context Switching Error in ElasticsearchCVE-2021-22134Mediumorg.elasticsearch:elasticsearch: Exposure of Sensitive Information to an Unauthorized ActorCVE-2020-13949Highorg.apache.thrift:libthrift: Uncontrolled Resource Consumption in Apache ThriftCVE-2021-20262Mediumorg.keycloak:keycloak-core: Keycloak Missing authentication for critical functionCVE-2020-13959Mediumorg.apache.velocity.tools:velocity-tools-parent: Cross-site scripting (XSS) in Apache Velocity ToolsCVE-2021-21364Mediumio.swagger:swagger-codegen: Generated Code Contains Local Information Disclosure VulnerabilityCVE-2021-21363Lowio.swagger:swagger-codegen: Generator Web Application: Local Privilege Escalation Vulnerability via System Temp DirectoryCVE-2020-27223Mediumorg.eclipse.jetty:jetty-server: DOS vulnerability for Quoted Quality CSV headersCVE-2021-21295Mediumio.netty:netty-codec-http2: Possible request smuggling in HTTP/2 due missing validationCVE-2021-21361Highcom.bmuschko:gradle-vagrant-plugin: Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-pluginCVE-2021-21331Lowcom.datadoghq:datadog-api-client: Local Information Disclosure VulnerabilityCVE-2020-13697Mediumorg.nanohttpd:nanohttpd-nanolets: NanoHTTPD Cross-site Scripting vulnerabilityCVE-2020-25649Highcom.fasterxml.jackson.core:jackson-databind: XML External Entity (XXE) Injection in Jackson DatabindCVE-2021-21479Highcom.sap.scimono:scimono-server: Remote Code Execution in SCIMonoCVE-2021-21290Mediumio.netty:netty-codec-http: Local Information Disclosure Vulnerability in Netty on Unix-Like systemsGHSA-W736-HF9P-QQH3Lowcom.amazonaws:aws-dynamodb-encryption-java: Key Caching behavior in the DynamoDB Encryption Client.CVE-2020-11979Highorg.apache.ant:ant: Code injection in Apache AntCVE-2021-21294Highorg.http4s:http4s-blaze-server_2.12: Unbounded connection acceptance in http4s-blaze-serverCVE-2021-21293Highorg.http4s:blaze-core_2.11: Unbounded connection acceptance leads to file handle exhaustionCVE-2021-21028Highcom.adobe.acs:acs-aem-commons: Reflected Cross-site Scripting in ACS CommonsCVE-2021-3137Mediumorg.xwiki.commons:xwiki-commons: Cross Site Scripting (XSS) in XWikiCVE-2020-8570Highio.kubernetes:client-java: Path Traversal in the Java Kubernetes ClientCVE-2021-20190Highcom.fasterxml.jackson.core:jackson-databind: Deserialization of untrusted data in jackson-databindCVE-2017-12626Highorg.apache.poi:poi: Denial of Service in Apache POI

Stop the waste.
Protect your environment with Kodem.