Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-14720Criticalcom.fasterxml.jackson.core:jackson-databind: XML External Entity Reference (XXE) in jackson-databindCVE-2018-14721Criticalcom.fasterxml.jackson.core:jackson-databind: Server-Side Request Forgery (SSRF) in jackson-databindCVE-2018-19362Criticalcom.fasterxml.jackson.core:jackson-databind: com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted DataCVE-2018-19361Criticalcom.fasterxml.jackson.core:jackson-databind: Deserialization of Untrusted Data in jackson-databindCVE-2018-19360Criticalcom.fasterxml.jackson.core:jackson-databind: Deserialization of Untrusted Data in jackson-databind due to polymorphic deserializationCVE-2018-14718Criticalcom.fasterxml.jackson.core:jackson-databind: Arbitrary Code Execution in jackson-databindCVE-2018-18893Mediumcom.hubspot.jinjava:jinjava: Jinjava calls getClassCVE-2018-20594Mediumorg.hswebframework.web:hsweb-commons: Moderate severity vulnerability that affects org.hswebframework.web:hsweb-commonsCVE-2018-20595Highorg.hswebframework.web:hsweb-commons: Cross-Site Request Forgery (CSRF) in hswebframework.web:hsweb-commonsCVE-2018-17197Mediumorg.apache.tika:tika-parsers: Apache Tika Denial of Service due to Infinite Loop in Tika's SQLite3ParserCVE-2016-1000031Criticalcommons-fileupload:commons-fileupload: Improper Access Control in commons-fileuploadCVE-2014-0050Highcommons-fileupload:commons-fileupload: Commons FileUpload Denial of service vulnerabilityCVE-2018-8009Highorg.apache.hadoop:hadoop-main: Path Traversal in HadoopCVE-2018-11766Highorg.apache.hadoop:hadoop-main: Arbitrary Command Execution in HadoopCVE-2017-15718Criticalorg.apache.hadoop:hadoop-main: Exposure of Sensitive Information in HadoopCVE-2017-15713Mediumorg.apache.hadoop:hadoop-main: Moderate severity vulnerability that affects org.apache.hadoop:hadoop-mainCVE-2017-3166Mediumorg.apache.hadoop:hadoop-main: Moderate severity vulnerability that affects org.apache.hadoop:hadoop-mainCVE-2018-11786Highorg.apache.karaf:apache-karaf: Improper Privilege Management in Apache KarafCVE-2018-14637Highorg.keycloak:keycloak-core: Improper Authentication in KeycloakCVE-2018-1000844Criticalcom.squareup.retrofit2:retrofit: XML External Entity (XXE) vulnerability in Square RetrofitCVE-2018-1000850Highcom.squareup.retrofit2:retrofit: Directory Traversal vulnerability in Square RetrofitCVE-2016-3092Highcommons-fileupload:commons-fileupload: High severity vulnerability that affects commons-fileupload:commons-fileuploadCVE-2018-1000873Mediumcom.fasterxml.jackson.datatype:jackson-datatype-jsr310: Moderate severity vulnerability that affects com.fasterxml.jackson.datatype:jackson-datatype-jsr353CVE-2018-1000854Criticalorg.esigate:esigate-core: Remote Code Execution in esigate-coreCVE-2018-1000836Criticalorg.bedework.caleng:bw-calendar-engine: XML External Entity (XXE) vulnerability in bw-calendar-engine

Stop the waste.
Protect your environment with Kodem.