Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-3164Highorg.apache.solr:solr-core: Server-Side Request Forgery (SSRF) in org.apache.solr:solr-coreCVE-2019-0192Criticalorg.apache.solr:solr-core: Critical severity vulnerability that affects org.apache.solr:solr-coreCVE-2019-3778Mediumorg.springframework.security.oauth:spring-security-oauth: spring-security-oauth and spring-security-oauth2 Open Redirect vulnerabilityCVE-2019-9658Mediumcom.puppycrawl.tools:checkstyle: Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyleCVE-2019-0200Highorg.apache.qpid:apache-qpid-broker-j: Improper Input Validation in Apache Qpid Broker-JCVE-2019-0187Criticalorg.apache.jmeter:ApacheJMeter: Unauthenticated Remote Code Execution in Apache JMeterCVE-2018-11793Highorg.apache.mesos:mesos: Stack Overflow in Apache MesosCVE-2019-9212Criticalcom.alipay.sofa:hessian: Incomplete List of Disallowed Inputs in SOFA-HessianCVE-2019-9142Mediumorg.b3log:symphony: Moderate severity vulnerability that affects org.b3log:symphonyCVE-2019-8331Mediumbootstrap: Bootstrap Vulnerable to Cross-Site ScriptingCVE-2018-1296Highorg.apache.hadoop:hadoop-main: Exposure of Sensitive Information to an Unauthorized Actor in HadoopCVE-2018-20242Mediumorg.apache.jspwiki:jspwiki-war: Cross-site Scripting in jspwiki-warCVE-2019-3774Loworg.springframework.batch:spring-batch-core: Low severity vulnerability that affects org.springframework.batch:spring-batch-coreCVE-2019-3773Criticalorg.springframework.ws:spring-ws: Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xmlCVE-2019-3772Loworg.springframework.integration:spring-integration-xml: Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and…CVE-2018-20677Mediumbootstrap: bootstrap Cross-site Scripting vulnerabilityCVE-2018-20676Mediumbootstrap: XSS vulnerability that affects bootstrapCVE-2016-10735Mediumbootstrap: Bootstrap Cross-site Scripting vulnerabilityCVE-2018-1320Highorg.apache.thrift:libthrift: Improper Input Validation in Apache ThriftCVE-2018-11798Mediumorg.apache.thrift:libthrift: Apache Thrift Node.js static web server sandbox escapeCVE-2018-11787Highorg.apache.karaf:apache-karaf: Improper Authentication in Apache KarafCVE-2018-11788Criticalorg.apache.karaf.specs:org.apache.karaf.specs.java.xml: XML External Entity Reference in Apache KarafCVE-2016-8750Mediumorg.apache.karaf:apache-karaf: Moderate severity vulnerability that affects org.apache.karaf:apache-karafCVE-2018-20433Criticalcom.mchange:c3p0: XML External Entity Reference in mchange:c3p0CVE-2018-14719Criticalcom.fasterxml.jackson.core:jackson-databind: Arbitrary Code Execution in jackson-databind

Stop the waste.
Protect your environment with Kodem.