Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-17571Criticallog4j:log4j: Deserialization of Untrusted Data in Log4jCVE-2017-5645Criticalorg.apache.logging.log4j:log4j: Deserialization of Untrusted Data in Log4jCVE-2019-12418Highorg.apache.tomcat.embed:tomcat-embed-core: Insufficiently Protected Credentials in Apache TomcatCVE-2019-17563Highorg.apache.tomcat.embed:tomcat-embed-core: In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attackGHSA-35FR-H7JR-HH86Mediumcom.linecorp.armeria:armeria: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in ArmeriaCVE-2019-16771Mediumcom.linecorp.armeria:armeria: Low severity vulnerability that affects com.linecorp.armeria:armeriaCVE-2019-12421Highorg.apache.nifi:nifi-web-security: Apache NiFi user log out issueCVE-2019-10083Mediumorg.apache.nifi:nifi-web-api: Apache NiFi process group information disclosureCVE-2019-10080Mediumorg.apache.nifi:nifi-security: Apache NiFi information disclosure by XXECVE-2019-17632Mediumorg.eclipse.jetty:jetty-server: Unescaped exception messages in error responses in JettyCVE-2018-11768Highorg.apache.hadoop:hadoop-main: user/group information can be corrupted across storing in fsimage and reading back from fsimageCVE-2019-10212Criticalio.undertow:undertow-core: Potential to access user credentials from the log files when debug logging enabledCVE-2019-0207Highorg.apache.tapestry:tapestry-core: Path traversal attack on Windows platformsCVE-2019-17531Criticalcom.fasterxml.jackson.core:jackson-databind: jackson-databind polymorphic typing issueCVE-2019-16943Criticalcom.fasterxml.jackson.core:jackson-databind: jackson-databind polymorphic typing issueCVE-2019-13236Mediumorg.opencms:opencms-core: XSS issues in the management interfaceCVE-2019-13235Mediumorg.opencms:opencms-core: XSS in login formCVE-2019-13237Mediumorg.opencms:opencms-core: Local file inclusion allows unauthorized access to internal resources in Alkacon OpenCmsCVE-2019-13234Mediumorg.opencms:opencms-core: XSS in search engineCVE-2019-12406Mediumorg.apache.cxf:cxf: Potential DOS attack due to unrestricted attachment count in messagesCVE-2019-12419Criticalorg.apache.cxf:cxf: Potential session hijack in Apache CXF CVE-2019-10755Mediumorg.pac4j:pac4j-saml: Use of Cryptographically Weak Pseudo-Random Number Generator in org.pac4j:pac4j-samlCVE-2019-16942Criticalcom.fasterxml.jackson.core:jackson-databind: Polymorphic Typing in FasterXML jackson-databindCVE-2017-15703Mediumorg.apache.nifi:nifi-framework-cluster-protocol: Denial of service via deserialization attack in nifiCVE-2019-11284Highio.projectreactor.netty:reactor-netty: Insufficiently Protected Credentials in Pivotal Reactor Netty

Stop the waste.
Protect your environment with Kodem.