Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-2670Mediumio.undertow:undertow-core: Moderate severity vulnerability that affects io.undertow:undertow-coreCVE-2018-1000644Criticalorg.eclipse.rdf4j:rdf4j-runtime: Eclipse RDF4j vulnerable to XML External EntityCVE-2018-10936Mediumorg.postgresql:pgjdbc-aggregate: Moderate severity vulnerability that affects org.postgresql:pgjdbc-aggregateCVE-2016-10726Highorg.dspace:dspace-xmlui: High severity vulnerability that affects org.dspace:dspace-xmluiCVE-2017-5617Highcom.kitfox.svg:svg-salamander: Server Side Request Forgery in svgSalamanderCVE-2017-15288Highorg.scala-lang:scala-compiler: High severity vulnerability that affects org.scala-lang:scala-compilerCVE-2017-14063Highorg.asynchttpclient:async-http-client: Improper Input Validation in async-http-clientCVE-2017-1000498Highcom.caverock:androidsvg: Android SVG vulnerable to XML External Entity (XXE)CVE-2017-1000208Highio.swagger:swagger-codegen: Deserialization of Untrusted Data in swagger-parserCVE-2017-1000207Highio.swagger:swagger-parser: Deserialization of Untrusted Data in swagger-codegenCVE-2018-1000529Mediumorg.grails.plugins:fields: Stored Cross Site Scripting in Grails Fields PluginCVE-2018-11775Highorg.apache.activemq:activemq-client: Improper Certificate Validation in Apache activemq-clientCVE-2018-1307Highorg.apache.juddi:juddi-client: Apache juddi-client vulnerable to XML External Entity (XXE)CVE-2018-1298Mediumorg.apache.qpid:apache-qpid-broker-j: Moderate severity vulnerability that affects org.apache.qpid:apache-qpid-broker-jCVE-2018-11771Mediumorg.apache.commons:commons-compress: Moderate severity vulnerability that affects org.apache.commons:commons-compressCVE-2017-15701Highorg.apache.qpid:qpid-broker: Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumptionCVE-2017-15702Criticalorg.apache.qpid:qpid-broker: Apache Qpid Broker vulnerable to authentication port spoofingCVE-2018-8039Highorg.apache.cxf:apache-cxf: Apache CXF TLS hostname verification does not work correctly with com.sun.net.ssl.*CVE-2016-4216Highcom.adobe.xmp:xmpcore: Moderate severity vulnerability that affects com.adobe.xmp:xmpcoreCVE-2017-7658Criticalorg.eclipse.jetty:jetty-server: Jetty vulnerable to authorization bypass due to inconsistent HTTP request handling (HTTP Request Smuggling)CVE-2017-7656Highorg.eclipse.jetty:jetty-server: Jetty vulnerable to cache poisoning due to inconsistent HTTP request handling (HTTP Request Smuggling)CVE-2016-4800Criticalorg.eclipse.jetty:jetty-server: Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted requestCVE-2018-12536Mediumorg.eclipse.jetty:jetty-server: Eclipse Jetty Server generates error message containing sensitive informationCVE-2017-9735Highorg.eclipse.jetty:jetty-server: Jetty vulnerable to exposure of sensitive information due to observable discrepancyCVE-2017-7657Criticalorg.eclipse.jetty:jetty-server: Critical severity vulnerability that affects org.eclipse.jetty:jetty-server

Stop the waste.
Protect your environment with Kodem.