Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-10093Mediumorg.apache.tika:tika-parsers: Allocation of Resources Without Limits or Throttling in Apache TikaCVE-2019-10094Highorg.apache.tika:tika-core: Allocation of Resources Without Limits or Throttling in Apache TikaCVE-2019-10184Highio.undertow:undertow-servlet: Undertow Missing Authorization when requesting a protected directory without trailing slashCVE-2019-14439Highcom.fasterxml.jackson.core:jackson-databind: Deserialization of untrusted data in FasterXML jackson-databindCVE-2019-14379Criticalcom.fasterxml.jackson.core:jackson-databind: Deserialization of untrusted data in FasterXML jackson-databindCVE-2018-11779Criticalorg.apache.storm:storm-kafka: Deserialization of Untrusted Data in Apache StormCVE-2015-7559Mediumorg.apache.activemq:activemq-client: Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQCVE-2019-0193Highorg.apache.solr:solr-core: XML External Entity (XXE) Injection in Apache SolrCVE-2018-15890Criticalorg.ethereum:ethereumj-core: Deserialization of Untrusted Data in EthereumJCVE-2019-10173Criticalcom.thoughtworks.xstream:xstream: Deserialization of Untrusted Data and Code Injection in xstreamCVE-2019-12814Mediumcom.fasterxml.jackson.core:jackson-databind: Deserialization of untrusted data in FasterXML jackson-databindCVE-2018-11307Criticalcom.fasterxml.jackson.core:jackson-databind: Deserialization of Untrusted Data in jackson-databindCVE-2019-0228Criticalorg.apache.pdfbox:pdfbox: Vulnerability that affects org.apache.pdfbox:pdfboxCVE-2019-9827Criticalio.hawt:hawtio-core: Server-Side Request Forgery in Hawt HawtioCVE-2019-9843Highcom.diffplug.spotless:spotless-plugin-gradle: Improper Restriction of XML External Entity Reference in DiffPlug SpotlessCVE-2019-12384Mediumcom.fasterxml.jackson.core:jackson-databind: Deserialization of Untrusted Data in FasterXML jackson-databindCVE-2019-3875Mediumorg.keycloak:keycloak-core: Improper Certificate Validation and Insufficient Verification of Data Authenticity in KeycloakCVE-2019-11272Highorg.springframework.security:spring-security-core: Insufficiently Protected Credentials and Improper Authentication in Spring SecurityCVE-2019-10072Highorg.apache.tomcat.embed:tomcat-embed-core: Improper Locking in Apache TomcatCVE-2017-15694Mediumorg.apache.geode:geode-core: Argument Injection in Apache Geode serverCVE-2019-5442Highro.pippo:pippo-jaxb: XML Entity Expansion in PippoCVE-2019-11269Mediumorg.springframework.security.oauth:spring-security-oauth: Open Redirect in Spring Security OAuthCVE-2019-3888Criticalio.undertow:undertow-core: Credential exposure through log files in UndertowCVE-2019-12741Mediumca.uhn.hapi.fhir:hapi-fhir-base: Cross-site Scripting in HAPI FHIRCVE-2019-10078Mediumorg.apache.jspwiki:jspwiki-war: Cross-site Scriptin in JSPWiki

Stop the waste.
Protect your environment with Kodem.