Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-10246Mediumorg.eclipse.jetty:jetty-server: Information Exposure vulnerability in Eclipse JettyCVE-2019-10247Mediumorg.eclipse.jetty:jetty-server: Installation information leak in Eclipse JettyCVE-2019-10241Mediumorg.eclipse.jetty:jetty-server: Cross-site Scripting in Eclipse JettyCVE-2019-5427Highcom.mchange:c3p0: Billion laughs attack in c3p0CVE-2019-11404Mediumio.arrow-kt:arrow-ank-gradle: Missing Encryption of Sensitive Data in arrow-kt ArrowCVE-2019-10686Criticalcom.ctrip.framework.apollo:apollo: Server-Side Request Forgery (SSRF) in com.ctrip.framework.apollo:apolloCVE-2019-0232Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat OS Command Injection vulnerabilityCVE-2019-3795Mediumorg.springframework.security:spring-security-core: Spring Security uses insufficiently random valuesCVE-2019-10240Highorg.eclipse.hawkbit:hawkbit-autoconfigure: Cleartext Transmission of Sensitive Information, Inclusion of Functionality from Untrusted Control Sphere , and Download of Code Without…CVE-2019-0225Highorg.apache.jspwiki:jspwiki-war: Improper Limitation of a Pathname ('Path Traversal') in org.apache.jspwiki:jspwiki-warCVE-2019-1010260Highcom.github.shyiko.ktlint:ktlint-core: High severity vulnerability that affects com.github.shyiko.ktlint:ktlint-coreCVE-2019-0212Highorg.apache.hbase:hbase: Improper Authorization in org.apache.hbase:hbaseCVE-2019-0224Mediumorg.apache.jspwiki:jspwiki-main: Moderate severity vulnerability that affects org.apache.jspwiki:jspwiki-mainCVE-2019-0222Highorg.apache.activemq:activemq-client: Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-clientCVE-2019-10648Criticalnet.sf.robocode:robocode.host: Improper Input Validation in net.sf.robocode:robocode.host allows for external service interactionCVE-2018-12545Highorg.eclipse.jetty:jetty-server: Uncontrolled Resource Consumption in org.eclipse.jetty:jetty-serverCVE-2018-12022Highcom.fasterxml.jackson.core:jackson-databind: jackson-databind Deserialization of Untrusted Data vulnerabilityCVE-2018-11767Highorg.apache.hadoop:hadoop-main: Improper Privilege Management in org.apache.hadoop:hadoop-mainCVE-2019-0191Mediumorg.apache.karaf:karaf: Moderate severity vulnerability that affects org.apache.karaf:apache-karaf and org.apache.karaf:karafCVE-2018-1324Mediumorg.apache.commons:commons-compress: Apache Commons Compress vulnerable to denial of service due to infinite loopCVE-2018-1334Mediumorg.apache.spark:spark-core_2.10: Exposure of Sensitive Information to an Unauthorized Actor in Apache SparkCVE-2018-8024Mediumorg.apache.spark:spark-core_2.10: Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URLCVE-2015-1772Highorg.apache.hive:hive: Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-serviceCVE-2016-3083Highorg.apache.hive:hive: org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service vulnerable to Improper Certificate Validation CVE-2017-12625Mediumorg.apache.hive:hive: Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service

Stop the waste.
Protect your environment with Kodem.