Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-14195Highcom.fasterxml.jackson.core:jackson-databind: Deserialization of untrusted data in Jackson DatabindCVE-2015-6420Highorg.apache.commons:commons-collections4: Insecure Deserialization in Apache Commons CollectionCVE-2019-10086Highcommons-beanutils:commons-beanutils: Insecure Deserialization in Apache Commons BeanutilsCVE-2018-10237Mediumcom.google.guava:guava-jdk5: Denial of Service in Google GuavaCVE-2017-7536Highorg.hibernate:hibernate-validator: Privilege Escalation in Hibernate ValidatorCVE-2020-11612Highio.netty:netty-handler: Denial of Service in NettyCVE-2018-15756Highorg.springframework:spring-core: Denial of Service in Spring FrameworkCVE-2020-5408Mediumorg.springframework.security:spring-security-core: Insufficient Entropy in Spring SecurityCVE-2012-0881Highxerces:xercesImpl: Denial of service in Apache Xerces2CVE-2009-2625Mediumxerces:xercesImpl: Denial of service in Apache Xerces2CVE-2020-1938Criticalorg.apache.tomcat.embed:tomcat-embed-core: Improper Privilege Management in TomcatCVE-2019-0199Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat Denial of Service vulnerabilityCVE-2018-12023Highcom.fasterxml.jackson.core:jackson-databind: Deserialization of Untrusted DataCVE-2019-17267Criticalcom.fasterxml.jackson.core:jackson-databind: Improper Input Validation in jackson-databindCVE-2014-0114Highcommons-beanutils:commons-beanutils: Arbitrary code execution in Apache Commons BeanUtilsCVE-2020-11112Highcom.fasterxml.jackson.core:jackson-databind: jackson-databind mishandles the interaction between serialization gadgets and typingCVE-2014-8122Mediumorg.jboss.weld:weld-core-bom: Information disclosure in JBoss WeldCVE-2020-7226Highorg.cryptacular:cryptacular: Denial of Service in CryptacularCVE-2019-17570Criticalorg.apache.xmlrpc:xmlrpc: Insecure Deserialization in Apache XML-RPCCVE-2019-17573Mediumorg.apache.cxf:apache-cxf: Reflected Cross-Site Scripting in Apache CXFCVE-2020-10683Criticalorg.dom4j:dom4j: dom4j allows External Entities by default which might enable XXE attacksCVE-2020-5407Highorg.springframework.security:spring-security-core: Signature wrapping vulnerability in Spring SecurityCVE-2020-5410Highorg.springframework.cloud:spring-cloud-config-server: Directory traversal attack in Spring Cloud ConfigCVE-2020-5405Mediumorg.springframework.cloud:spring-cloud-config-server: Directory traversal attack in Spring Cloud ConfigCVE-2020-1963Criticalorg.apache.ignite:ignite-core: File system access via H2 in Apache Ignite

Stop the waste.
Protect your environment with Kodem.