Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-12798Mediumch.qos.logback:logback-core: QOS.CH logback-core Expression Language Injection vulnerabilityCVE-2024-12801Lowch.qos.logback:logback-core: QOS.CH logback-core Server-Side Request Forgery vulnerabilityCVE-2024-56128Loworg.apache.kafka:kafka_2.13: Apache Kafka's SCRAM implementation Incorrectly Implements Authentication AlgorithmCVE-2023-37940Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy pageCVE-2024-11993Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to Cross-site ScriptingCVE-2024-12539Mediumorg.elasticsearch:elasticsearch: Elasticsearch Incorrect Authorization vulnerabilityCVE-2024-49194Highcom.databricks:databricks-jdbc: Databricks JDBC Driver Command Injection vulnerabilityCVE-2024-54677Mediumorg.apache.tomcat:tomcat: Apache Tomcat Uncontrolled Resource Consumption vulnerabilityCVE-2024-50379Highorg.apache.tomcat:tomcat-catalina: Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilityCVE-2024-35230Mediumorg.geoserver.web:gs-web-app: Welcome and About GeoServer pages communicate version and revision informationCVE-2024-55887Highorg.fhir:ucum: Ucum-java has an XXE vulnerability in XML parsingCVE-2024-55662Criticalorg.xwiki.platform:xwiki-platform-repository-server-ui: XWiki allows remote code execution through the extension sheetCVE-2024-55663Highorg.xwiki.platform:xwiki-platform-distribution-war: XWiki Platform has an SQL injection in getdocuments.vm with sort parameterCVE-2024-55875Criticalorg.http4k:http4k-format-xml: http4k has a potential XXE (XML External Entity Injection) vulnerabilityCVE-2024-55876Mediumorg.xwiki.platform:xwiki-platform-scheduler-ui: XWiki's scheduler in subwiki allows scheduling operations for any main wiki userCVE-2024-55877Criticalorg.xwiki.platform:xwiki-platform-help-ui: XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosListCVE-2024-55879Criticalorg.xwiki.platform:xwiki-platform-administration-ui: XWiki allows RCE from script right in configurable sectionsCVE-2024-12397Highio.quarkus.http:quarkus-http-core: io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie SmugglingCVE-2024-53677Criticalorg.apache.struts:struts2-core: Apache Struts file upload logic is flawedCVE-2024-54140Lowdev.sigstore:sigstore-java: sigstore-java has a vulnerability with bundle verificationCVE-2022-41137Highorg.apache.hive:hive-exec: Apache Hive: Deserialization of untrusted data when fetching partitions from the MetastoreCVE-2024-38829Mediumorg.springframework.ldap:spring-ldap-core: Spring LDAP data exposure vulnerabilityCVE-2024-45106Highorg.apache.ozone:ozone: Apache Ozone: Improper authentication when generating S3 secretsCVE-2024-53990Criticalorg.asynchttpclient:async-http-client: AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`sCVE-2024-52800Loworg.verapdf:core: veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability

Stop the waste.
Protect your environment with Kodem.