Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-7661Mediumorg.apache.cxf.fediz:fediz-spring2: Moderate severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9, and…CVE-2014-3651Highorg.keycloak:keycloak-core: Keycloak vulnerable to uncontrolled resource consumptionCVE-2017-12161Mediumorg.keycloak:keycloak-core: Moderate severity vulnerability that affects org.keycloak:keycloak-coreCVE-2018-10912Mediumorg.keycloak:keycloak-core: Moderate severity vulnerability that affects org.keycloak:keycloak-coreCVE-2017-2582Mediumorg.keycloak:keycloak-core: keycloak-core discloses system propertiesCVE-2017-2646Highorg.keycloak:keycloak-core: Keycloak vulnerable to infinite loop based Denial of ServiceCVE-2016-8609Highorg.keycloak:keycloak-core: Improper Authentication in org.keycloak:keycloak-coreCVE-2016-8629Mediumorg.keycloak:keycloak-core: Moderate severity vulnerability that affects org.keycloak:keycloak-coreCVE-2017-2585Mediumorg.keycloak:keycloak-core: keycloak-core vulnerable to timing attacks against JWS token verificationCVE-2017-3163Highorg.apache.solr:solr-core: Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-coreCVE-2016-5007Highorg.springframework:spring-core: Spring Security and Spring Framework may not recognize certain paths that should be protectedCVE-2015-5211Highorg.springframework:spring-core: Files or Directories Accessible to External Parties in org.springframework:spring-coreCVE-2015-3192Mediumorg.springframework:spring-web: Pivotal Spring Framework DoS Attack with XML InputCVE-2015-0201Mediumorg.springframework:spring-core: Moderate severity vulnerability that affects org.springframework:spring-coreCVE-2018-1275Criticalorg.springframework:spring-messaging: Spring Framework has Improperly Implemented Security Check for StandardCVE-2018-1272Highorg.springframework:spring-core: Possible privilege escalation in org.springframework:spring-coreCVE-2018-1271Mediumorg.springframework:spring-core: Path Traversal in org.springframework:spring-coreCVE-2018-1270Criticalorg.springframework:spring-messaging: Spring Framework allows applications to expose STOMP over WebSocket endpointsCVE-2018-1258Highorg.springframework:spring-core: Spring Framework when used in combination with any versions of Spring Security contains an authorization bypassCVE-2018-1257Mediumorg.springframework:spring-core: Denial of Service in org.springframework:spring-coreCVE-2018-1199Mediumorg.springframework:spring-core: Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and…CVE-2017-12629Criticalorg.apache.solr:solr-core: Remote code execution occurs in Apache SolrCVE-2018-8010Mediumorg.apache.solr:solr-core: There is a XML external entity expansion (XXE) vulnerability in Apache Solr config filesCVE-2018-1308Highorg.apache.solr:solr-core: There is a XML external entity expansion (XXE) vulnerability in Apache Solr CVE-2018-8026Mediumorg.apache.solr:solr-core: XML external entity expansion in org.apache.solr:solr-core

Stop the waste.
Protect your environment with Kodem.