Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-11776Highorg.apache.struts:struts2-core: Apache Struts vulnerable to remote command execution (RCE) due to improper input validationCVE-2017-5638Criticalorg.apache.struts:struts2-core: Apache Struts vulnerable to remote arbitrary command execution due to improper input validationCVE-2016-4977Highorg.springframework.security.oauth:spring-security-oauth2: Spring Security OAuth vulnerable to remote code execution (RCE) via specially crafted request using whitelabel viewsCVE-2018-11087Mediumorg.springframework.amqp:spring-amqp: Moderate severity vulnerability that affects com.rabbitmq:amqp-client and org.springframework.amqp:spring-amqpCVE-2018-1196Mediumorg.springframework.boot:spring-boot: Moderate severity vulnerability that affects org.springframework.boot:spring-bootCVE-2018-1261Mediumorg.springframework.integration:spring-integration-zip: Path traversal in org.springframework.integration:spring-integration-zipCVE-2018-1260Criticalorg.springframework.security.oauth:spring-security-oauth2: Spring Security OAuth vulnerable to remote code execution (RCE)CVE-2018-8025Highorg.apache.hbase:hbase-thrift: Race condition in org.apache.hbase:hbase-thriftCVE-2015-1836Highorg.apache.hbase:hbase: High severity vulnerability that affects org.apache.hbase:hbaseCVE-2016-1000345Mediumorg.bouncycastle:bcprov-jdk14: Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15CVE-2016-1000344Highorg.bouncycastle:bcprov-jdk14: In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB modeCVE-2016-7051Highcom.fasterxml.jackson.dataformat:jackson-dataformat-xml: jackson-dataformat-xml vulnerable to server side request forgery (SSRF)CVE-2016-3720Criticalcom.fasterxml.jackson.dataformat:jackson-dataformat-xml: jackson-dataformat-xml vulnerable to XML external entity (XXE)CVE-2017-17485Criticalcom.fasterxml.jackson.core:jackson-databind: jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypassCVE-2017-15095Criticalcom.fasterxml.jackson.core:jackson-databind: jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code executionCVE-2015-2918Mediumcom.orientechnologies:orientdb-studio: OrientDB Studio web management interface is vulnerable to clickjacking attacksCVE-2015-2913Mediumcom.orientechnologies:orientdb-server: OrientDB Server Community Edition uses insufficiently random values to generate session IDsCVE-2015-2912Highcom.orientechnologies:orientdb-studio: OrientDB-Server vulnerable to Cross-Site Request ForgeryCVE-2017-11467Criticalcom.orientechnologies:orientdb-core: OrientDB vulnerable to Improper Privilage Management leading to arbitrary command injectionCVE-2017-14735Mediumorg.owasp.antisamy:antisamy: OWASP AntiSamy Cross-site Scripting vulnerabilityCVE-2016-10006Mediumorg.owasp.antisamy:antisamy: OWASP AntiSamy vulnerable to Cross-site ScriptingCVE-2017-12631Mediumorg.apache.cxf.fediz:fediz-spring2: Moderate severity vulnerability that affects org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and…CVE-2016-4464Highorg.apache.cxf.fediz:fediz-spring: High severity vulnerability that affects org.apache.cxf.fediz:fediz-spring and org.apache.cxf.fediz:fediz-spring2CVE-2015-5175Highorg.apache.cxf.fediz:fediz-idp: Apache CXF Fediz application plugins are vulnerable to Denial of Service (DoS) attacksCVE-2018-8038Highorg.apache.cxf.fediz:fediz-spring: High severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9,…

Stop the waste.
Protect your environment with Kodem.