Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-17519Highorg.apache.flink:flink-runtime_2.11: Path Traversal in Apache FlinkCVE-2021-21234Higheu.hinsch:spring-boot-actuator-logview: Directory Traversal in spring-boot-actuator-logviewCVE-2020-26282Highcom.browserup:browserup-proxy: Server-Side Template InjectionCVE-2020-26258Mediumcom.thoughtworks.xstream:xstream: Server-Side Forgery Request can be activated unmarshalling with XStreamCVE-2020-26259Mediumcom.thoughtworks.xstream:xstream: XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshallingCVE-2020-35460Mediumnet.sf.mpxj:mpxj: MPXJ path Traversal vulnerabilityCVE-2020-17521Mediumorg.codehaus.groovy:groovy: Information Disclosure in Apache GroovyCVE-2020-26234Highorg.opencastproject:opencast-kernel: Disabled Hostname Verification in OpencastCVE-2020-27218Mediumorg.eclipse.jetty:jetty-server: Buffer not correctly recycled in Gzip Request inflationCVE-2020-26238Criticalcom.cronutils:cron-utils: Template injection in cron-utilsCVE-2020-26217Highcom.thoughtworks.xstream:xstream: XStream can be used for Remote Code ExecutionGHSA-Q76J-58CX-WP5VHighnet.ripe.rpki:rpki-validator-3: Vulnerability in RPKI manifest validationCVE-2017-15708Criticalorg.apache.synapse:synapse-core: Remote Code Execution in Apache SynapseCVE-2020-27216Highorg.mortbay.jetty:jetty-webapp: Local Temp Directory Hijacking VulnerabilityGHSA-8HXH-R6F7-JF45Loworg.http4s:http4s-async-http-client_2.13: Memory exhaustion in http4s-async-http-client with large or malicious compressed responsesCVE-2020-15252Highorg.xwiki.platform:xwiki-platform-oldcore: RCE in XWikiCVE-2020-8929Mediumcom.google.crypto.tink:tink: Ciphertext Malleability Issue in Tink JavaCVE-2020-15250Mediumjunit:junit: TemporaryFolder on unix-like systems does not limit access to created filesCVE-2012-5784Mediumorg.apache.axis:axis: Man-in-the-middle attack in Apache AxisCVE-2020-15170Highcom.ctrip.framework.apollo:apollo-core: Potential access control security issue in apollo-adminserviceGHSA-Q3VW-4JX3-RRR2Lowdev.personnummer:personnummer: personnummer/java vulnerable to Improper Input ValidationCVE-2016-9879Highorg.springframework.security:spring-security-core: Security Constraint Bypass in Spring SecurityCVE-2014-3527Criticalorg.springframework.security:spring-security-core: Authorization Bypass in Spring SecurityCVE-2015-0254Highorg.apache.taglibs:taglibs-standard: XXE in Apache Standard TaglibsCVE-2020-1945Mediumorg.apache.ant:ant: Sensitive Data Exposure in Apache Ant

Stop the waste.
Protect your environment with Kodem.