Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2015-3271Mediumorg.apache.tika:tika-server: Apache Tika Server exposes sensitive informationCVE-2018-1339Mediumorg.apache.tika:tika-parsers: org.apache.tika:tika-parsers has an Infinite Loop vulnerabilityCVE-2018-1335Highorg.apache.tika:tika-core: Command injection in org.apache.tika:tika-coreCVE-2018-11796Highorg.apache.tika:tika-core: Apache Tika is vulnerable to entity expansions which can lead to a denial of service attackCVE-2015-5262Mediumorg.apache.httpcomponents:httpclient: Denial of service vulnerability in org.apache.httpcomponents:httpclientCVE-2012-6153Highorg.apache.httpcomponents:httpclient: Improper certificate validation in org.apache.httpcomponents:httpclientCVE-2014-3577Mediumorg.apache.httpcomponents:httpclient: Improper Verification of Cryptographic Signature in org.apache.httpcomponents:httpclientCVE-2014-1868Mediumorg.restlet.jse:org.restlet: Moderate severity vulnerability that affects org.restlet.jse:org.restletCVE-2017-14868Highorg.restlet.jse:org.restlet.ext.jaxrs: Restlet Framework Ja-rs extension is vulnerable to XXE when using SimpleXMLProviderCVE-2017-14949Highorg.restlet.jse:org.restlet: Restlet Framework allows remote attackers to access arbitrary files via a crafted REST API HTTP requestCVE-2018-12418Mediumcom.github.junrar:junrar: Junrar vulnerable to Infinite LoopCVE-2014-0003Highorg.apache.camel:camel-core: Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methodsCVE-2014-0002Highorg.apache.camel:camel-core: Apache Camel's XSLT component allows remote attackers to read arbitrary filesCVE-2017-5643Highorg.apache.camel:camel-core: Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.CVE-2016-8749Criticalorg.apache.camel:camel-jackson: Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacksCVE-2015-5348Highorg.apache.camel:camel-jetty: Apache Camel can allow remote attackers to execute arbitrary commandsCVE-2015-5344Criticalorg.apache.camel:camel-xstream: Camel-xstream component in Apache Camel can allow remote attackers to execute arbitrary commands CVE-2015-0264Mediumorg.apache.camel:camel-core: Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile objectCVE-2015-0263Mediumorg.apache.camel:camel-core: Apache Camel XML External Entity vulnerabilityCVE-2018-8041Mediumorg.apache.camel:camel-mail: Apache Camel's Mail is vulnerable to path traversalCVE-2018-8027Criticalorg.apache.camel:camel-core: Apache is vulnerable to XXE in XSD validation processorCVE-2017-12634Criticalorg.apache.camel:camel-castor: Camel-castor component in Apache Camel is vulnerable to Java object de-serialisationCVE-2018-8018Criticalorg.apache.ignite:ignite-core: Code execution via deserialization in org.apache.ignite:ignite-coreCVE-2018-1295Criticalorg.apache.ignite:ignite-core: Apache serialization mechanism does not have a list of classes allowed for serialization/deserializationCVE-2016-6805Mediumorg.apache.ignite:ignite-core: Moderate severity vulnerability that affects org.apache.ignite:ignite-core

Stop the waste.
Protect your environment with Kodem.