Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-20444Criticalorg.jboss.netty:netty: HTTP Request Smuggling in NettyCVE-2019-20445Mediumio.netty:netty-handler: HTTP Request Smuggling in NettyCVE-2019-19703Mediumio.ktor:ktor-client-core: URL Redirection to Untrusted Site (Open Redirect) in KtorCVE-2019-17558Highorg.apache.solr:solr-core: Improper Input Validation in Apache SolrCVE-2019-10172Highorg.codehaus.jackson:jackson-mapper-asl: Improper Restriction of XML External Entity Reference in jackson-mapper-aslCVE-2020-1925Highorg.apache.olingo:odata-client-core: Server-Side Request Forgery (SSRF) in Apache OlingoCVE-2019-17556Criticalorg.apache.olingo:odata-client-proxy: Deserialization of Untrusted Data in Apache OlingoCVE-2019-17554Mediumorg.apache.olingo:odata-client-core: Improper Restriction of XML External Entity Reference in Apache OlingoCVE-2019-17555Highorg.apache.olingo:odata-client-core: Improper input validation in Apache OlingoCVE-2019-12422Highorg.apache.shiro:shiro-core: Improper input validation in Apache ShiroCVE-2019-10782Mediumcom.puppycrawl.tools:checkstyle: XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))CVE-2020-5228Highorg.opencastproject:opencast-oaipmh-api: Unauthenticated Access Via OAI-PMHCVE-2020-5229Loworg.opencastproject:opencast-common-jpa-impl: Password Hashing: Do not use MD5CVE-2020-5230Mediumorg.opencastproject:base: Unsafe Identifiers in OpencastCVE-2020-5222Mediumorg.opencastproject:opencast-kernel: Hard-Coded Key Used For Remember-me Token in OpencastCVE-2020-5231Mediumorg.opencastproject:opencast-kernel: Users with ROLE_COURSE_ADMIN can create new users in OpencastCVE-2020-5206Criticalorg.opencastproject:opencast-kernel: Authentication Bypass For Endpoints With Anonymous Access in OpencastCVE-2019-12409Criticalorg.apache.solr:solr-core: Unrestricted upload of file with dangerous type in Apache SolrCVE-2020-5207Lowio.ktor:ktor-client-cio: Request smuggling is possible when both chunked TE and content length specifiedCVE-2019-10770Mediumio.ratpack:ratpack-core: Default development error handler in Ratpack is vulnerable to HTML content injection (XSS)CVE-2019-10158Criticalorg.infinispan:infinispan-core: Improper implementation of the session fixation protection in InfinispanCVE-2020-5397Mediumorg.springframework:spring-webmvc: CSRF attack via CORS preflight requests with Spring MVC or Spring WebFluxCVE-2020-5398Highorg.springframework:spring-webmvc: RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux ApplicationCVE-2019-10070Mediumorg.apache.atlas:apache-atlas: Stored XSS in Apache AtlasCVE-2019-10219Mediumorg.hibernate.validator:hibernate-validator: The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks

Stop the waste.
Protect your environment with Kodem.