Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-17297Highcn.hutool:hutool-parent: Unzip function in ZipUtil.java in Hutool allows remote attackers to overwrite arbitrary files via directory traversalCVE-2018-8023Mediumorg.apache.mesos:mesos: Moderate severity vulnerability that affects org.apache.mesos:mesosCVE-2018-17785Highcom.github.blynkkk:blynk-server: In blynk-server a Directory Traversal existsCVE-2018-1332Mediumorg.apache.storm:storm-core: Moderate severity vulnerability that affects org.apache.storm:storm-coreCVE-2018-1331Highorg.apache.storm:storm-core: Code execution in org.apache.storm:storm-coreCVE-2017-9799Highorg.apache.storm:storm-core: Apache Storm it is possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, userCVE-2018-15531Criticalnet.bull.javamelody:javamelody-core: JavaMelody has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.CVE-2018-11797Mediumorg.apache.pdfbox:pdfbox: In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computationCVE-2016-2175Highorg.apache.pdfbox:pdfbox: High severity vulnerability that affects org.apache.pdfbox:pdfboxCVE-2018-18389Criticalorg.neo4j:neo4j-enterprise: Incorrect access control in Neo4j Enterprise Database Server via LDAP authenticationCVE-2018-1274Highorg.springframework.data:spring-data-commons: Spring Data Commons contain a property path parser vulnerability caused by unlimited resource allocationCVE-2018-1259Highorg.springframework.data:spring-data-commons: Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML…CVE-2018-1273Criticalorg.springframework.data:spring-data-commons: Spring Data Commons remote code injection vulnerabilityCVE-2017-7677Mediumorg.apache.ranger:ranger: Moderate severity vulnerability that affects org.apache.ranger:rangerCVE-2017-7676Criticalorg.apache.ranger:ranger: Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '' wildcard characterCVE-2018-11778Highorg.apache.ranger:ranger: UnixAuthenticationService in Apache Ranger was updated to correctly handle user input to avoid Stack-based buffer overflowCVE-2016-8746Mediumorg.apache.ranger:ranger-plugins-common: Apache Ranger policy engine incorrectly matches paths in certain conditionsCVE-2016-8751Mediumorg.apache.ranger:ranger: Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policiesCVE-2016-6815Mediumorg.apache.ranger:ranger: Moderate severity vulnerability that affects org.apache.ranger:rangerCVE-2016-5395Mediumorg.apache.ranger:ranger: Apache Ranger allows remote authenticated administrators to inject arbitrary web script or HTMLCVE-2016-2174Highorg.apache.ranger:ranger: SQL injection vulnerability in the policy admin tool in Apache RangerCVE-2016-0733Criticalorg.apache.ranger:ranger: The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a passwordCVE-2018-8037Mediumorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat Race Condition vulnerabilityCVE-2018-8034Highorg.apache.tomcat.embed:tomcat-embed-core: The host name verification missing in Apache TomcatCVE-2018-8014Criticalorg.apache.tomcat.embed:tomcat-embed-core: The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins

Stop the waste.
Protect your environment with Kodem.