Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-1336Highorg.apache.tomcat.embed:tomcat-embed-core: In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder CVE-2018-1305Mediumorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat information exposure vulnerabilityCVE-2018-1304Mediumorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat unauthorized access vulnerabilityCVE-2018-11784Mediumorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat Open Redirect vulnerabilityCVE-2017-12615Highorg.apache.tomcat.embed:tomcat-embed-core: When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the serverCVE-2015-7940Mediumorg.bouncycastle:bcprov-jdk15: Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15CVE-2016-1000352Highorg.bouncycastle:bcprov-jdk14: In Bouncy Castle JCE Provider the ECIES implementation allowed the use of ECB modeCVE-2016-1000346Loworg.bouncycastle:bcprov-jdk14: In Bouncy Castle JCE Provider the other party DH public key is not fully validatedCVE-2016-1000343Highorg.bouncycastle:bcprov-jdk14: In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default valuesCVE-2016-1000342Highorg.bouncycastle:bcprov-jdk14: In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verificationCVE-2016-1000341Mediumorg.bouncycastle:bcprov-jdk14: Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15CVE-2016-1000340Highorg.bouncycastle:bcprov-jdk14: The Bouncy Castle JCE Provider carry a propagation bugCVE-2016-1000339Mediumorg.bouncycastle:bcprov-jdk14: Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15CVE-2016-1000338Highorg.bouncycastle:bcprov-jdk14: In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validateCVE-2018-1000613Criticalorg.bouncycastle:bcprov-jdk15on: Deserialization of Untrusted Data in Bouncy castleCVE-2018-12542Criticalio.vertx:vertx-web: Eclipse Vert.x does not properly neutralize '' (forward slashes) sequences that can resolve to an external locationCVE-2018-12544Mediumio.vertx:vertx-core: Moderate severity vulnerability that affects io.vertx:vertx-coreCVE-2018-12541Mediumio.vertx:vertx-core: Excessive memory allocationCVE-2018-12540Highio.vertx:vertx-web: High severity vulnerability that affects io.vertx:vertx-webCVE-2018-1338Mediumorg.apache.tika:tika-core: Moderate severity vulnerability that affects org.apache.tika:tika-coreCVE-2018-8017Mediumorg.apache.tika:tika-core: Comparison errorr in org.apache.tika:tika-coreCVE-2018-11762Mediumorg.apache.tika:tika-core: Moderate severity vulnerability that affects org.apache.tika:tika-coreCVE-2018-11761Highorg.apache.tika:tika-core: High severity vulnerability that affects org.apache.tika:tika-coreCVE-2016-6809Criticalorg.apache.tika:tika-core: Apache Tika allows Java code execution for serialized objects embedded in MATLAB filesCVE-2016-4434Highorg.apache.tika:tika-core: Apache Tika does not properly initialize the XML parser or choose handlers

Stop the waste.
Protect your environment with Kodem.