Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-15171Loworg.xwiki.platform:xwiki-platform-oldcore: Users with SCRIPT right can execute arbitrary code in XWikiCVE-2012-6708Mediumjquery: Cross-Site Scripting in jqueryCVE-2020-12480Mediumcom.typesafe.play:play_2.12: CSRF in Play FrameworkCVE-2020-5413Criticalorg.springframework.integration:spring-integration-core: Code execution in Spring IntegrationCVE-2019-17638Criticalorg.eclipse.jetty:jetty-server: Operation on a Resource after Expiration or Release in Jetty ServerCVE-2020-11994Highorg.apache.camel:camel-robotframework: Server side template injection in Apache CamelCVE-2020-1937Mediumorg.apache.kylin:kylin-server-base: SQL Injection in KylinCVE-2020-1956Highorg.apache.kylin:kylin-core-common: Command Injection in KylinCVE-2020-13926Criticalorg.apache.kylin:kylin-server-base: SQL Injection in KylinCVE-2020-13925Criticalorg.apache.kylin:kylin-server-base: Command Injection in KylinGHSA-MM44-WC5P-WQHQHighcom.upokecenter:cbor: Denial of service due to reference expansion in versions earlier than 4.0CVE-2020-15231Loworg.mapfish.print:print-lib: XSS in Mapfish Print relating to JSONP supportCVE-2020-15232Criticalorg.mapfish.print:print-lib: XXE attack in Mapfish PrintCVE-2019-13990Criticalorg.quartz-scheduler:quartz: XML external entity injection in Terracotta Quartz SchedulerCVE-2019-17572Mediumorg.apache.rocketmq:rocketmq-broker: Directory traversal in Apache RocketMQCVE-2019-2692Mediummysql:mysql-connector-java: Privilege escalation in mysql-connector-javCVE-2017-7957Highcom.thoughtworks.xstream:xstream: Denial of service in XStreamCVE-2016-3674Highcom.thoughtworks.xstream:xstream: XML External Entity Injection in XStreamCVE-2014-3488Mediumio.netty:netty-handler: Denial of service in NettyCVE-2015-2156Highio.netty:netty-parent: Information Exposure in NettyCVE-2018-5968Highcom.fasterxml.jackson.core:jackson-databind: Deserialization of Untrusted Data in jackson-databindCVE-2020-15087Highio.prestosql:presto-server: Privilege escalation in PrestoCVE-2020-14061Highcom.fasterxml.jackson.core:jackson-databind: Deserialization of untrusted data in Jackson DatabindCVE-2020-14062Highcom.fasterxml.jackson.core:jackson-databind: Deserialization of untrusted data in Jackson DatabindCVE-2020-14060Highcom.fasterxml.jackson.core:jackson-databind: Deserialization of untrusted data in Jackson Databind

Stop the waste.
Protect your environment with Kodem.