Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-10077Mediumorg.apache.jspwiki:jspwiki-war: Cross-site Scripting in JSPWikiCVE-2019-10076Mediumorg.apache.jspwiki:jspwiki-war: Cross-Site Scripting in JSPWikiCVE-2019-3802Mediumorg.springframework.data:spring-data-jpa: Improper Neutralization of Wildcards or Matching SymbolsCVE-2018-8029Highorg.apache.hadoop:hadoop-main: Privilege escalation vulnerability in Apache HadoopCVE-2019-0221Mediumorg.apache.tomcat.embed:tomcat-embed-core: Cross-site scripting in Apache TomcatCVE-2019-0201Mediumorg.apache.zookeeper:zookeeper: Access control bypass in Apache ZooKeeperCVE-2019-0188Highorg.apache.camel:camel-core: XML External Entity injection in Apache CamelCVE-2019-11082Highde.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl: Path Traversal in DKPro CoreCVE-2013-7285Criticalcom.thoughtworks.xstream:xstream: Command Injection in XstreamCVE-2019-12086Highcom.fasterxml.jackson.core:jackson-databind: Information exposure in FasterXML jackson-databindCVE-2019-3799Mediumorg.springframework.cloud:spring-cloud-config-server: Path Traversal in Spring Cloud ConfigCVE-2019-3797Mediumorg.springframework.data:spring-data-jpa: Exposure of Sensitive Information to an Unauthorized Actor and SQL Injection in Spring Data JPACVE-2019-0227Highorg.apache.axis:axis: Server Side Request Forgery in Apache AxisCVE-2019-11808Lowio.ratpack:ratpack-session: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in RatpackCVE-2018-17201Highorg.apache.sanselan:sanselan: Improper Input Validation in Apache SanselanCVE-2018-17202Highorg.apache.sanselan:sanselan: Infinite Loop in Apache SanselanCVE-2018-8035Mediumorg.apache.uima:uima-ducc-web: Cross-site Scripting in Apache UIMACVE-2019-0213Mediumorg.apache.archiva:archiva: Cross-site scripting in Apache ArchivaCVE-2019-0214Mediumorg.apache.archiva:archiva: Improper Input Validation in Apache ArchivaCVE-2019-0194Highorg.apache.camel:camel-core: Path Traversal in Apache CamelCVE-2019-3868Mediumorg.keycloak:keycloak-core: Exposure of Sensitive Information to an Unauthorized Actor in KeycloakCVE-2019-11358Mediumjquery-rails: XSS in jQuery as used in Drupal, Backdrop CMS, and other productsCVE-2018-1328Mediumorg.apache.zeppelin:zeppelin: Cross-site Scripting in Apache ZeppelinCVE-2017-12619Highorg.apache.zeppelin:zeppelin: Session Fixation in Apache ZeppelinCVE-2018-1317Highorg.apache.zeppelin:zeppelin: Improper Authentication in Apache Zeppelin

Stop the waste.
Protect your environment with Kodem.