Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-1337Criticalorg.apache.directory.api:apache-ldap-api: Credential leak in org.apache.directory.api:apache-ldap-apiCVE-2017-12612Highorg.apache.spark:spark-core_2.11: Apache Spark Deserialization of Untrusted Data vulnerabilityCVE-2017-7678Mediumorg.apache.spark:spark-core_2.11: Moderate severity vulnerability that affects org.apache.spark:spark-core_2.10 and org.apache.spark:spark-core_2.11CVE-2018-18853Highio.spray:spray-json_2.12: Uncontrolled Resource Consumption in spray-json when parsing decimal digit fieldsCVE-2018-11770Mediumorg.apache.spark:spark-core_2.11: org.apache.spark:spark-core_2.10 and org.apache.spark:spark-core_2.11 Improper Authentication vulnerabilityCVE-2018-18854Highio.spray:spray-json_2.12: Uncontrolled Resource Consumption in spray-jsonCVE-2018-1321Highorg.apache.syncope:syncope-core: High severity vulnerability that affects org.apache.syncope:syncope-coreCVE-2018-1322Mediumorg.apache.syncope:syncope-core: Exposure of Sensitive Information to an Unauthorized Actor in Apache syncope-copeCVE-2018-17184Mediumorg.apache.syncope:syncope-core: Improper Control of Interaction Frequency in Apache syncope-coreCVE-2018-17186Highorg.apache.syncope:syncope-core: Improper Restriction of XML External Entity Reference in org.apache.syncope:syncope-coreCVE-2018-18830Criticalnet.mingsoft:ms-mcms: Unrestricted Upload of File with Dangerous Type in mingsoft:ms-mcmsCVE-2018-18831Highnet.mingsoft:ms-mcms: Path Traversal in minsoft:ms-mcmsCVE-2018-8006Mediumorg.apache.activemq:activemq-web-console: Apache ActiveMQ web console vulnerable to Cross-site ScriptingCVE-2018-18628Criticalro.pippo:pippo-core: Deserialization of Untrusted Data in PippoCVE-2017-18349Criticalcom.alibaba:fastjson: Improper Input Validation in alilibaba:fastjsonCVE-2018-18531Criticalcom.github.penggle:kaptcha: Use of Insufficiently Random Values in penggle:kaptchaCVE-2017-1000118Highcom.typesafe.akka:akka-http-core_2.12: Improper Restriction of Operations within the Bounds of a Memory Buffer in akka-http-coreCVE-2017-1000034Highcom.typesafe.akka:akka-actor: Akka Java Serialization vulnerabilityCVE-2018-16115Criticalcom.typesafe.akka:akka-actor_2.11: Cryptographically Weak Pseudo-Random Number Generator (PRNG) in akka-actorCVE-2018-16131Highcom.typesafe.akka:akka-http-core_2.12: High severity vulnerability that affects com.typesafe.akka:akka-http-core_2.11 and com.typesafe.akka:akka-http-core_2.12CVE-2018-15758Highorg.springframework.security.oauth:spring-security-oauth2: Authorization bypass in org.springframework.security.oauth:spring-security-oauth2CVE-2018-12537Mediumio.vertx:vertx-core: Moderate severity vulnerability that affects io.vertx:vertx-coreCVE-2018-9159Mediumcom.sparkjava:spark-core: Moderate severity vulnerability that affects com.sparkjava:spark-coreCVE-2018-1047Mediumorg.wildfly:wildfly-undertow: Improper Input Validation in org.wildfly:wildfly-undertowCVE-2017-2666Mediumio.undertow:undertow-core: Undertow-core vulnerable to HTTP Request Smuggling

Stop the waste.
Protect your environment with Kodem.