Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-52550Highorg.jenkins-ci.plugins.workflow:workflow-cps: Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin CVE-2024-52549Mediumorg.jenkins-ci.plugins:script-security: Missing permission check in Jenkins Script Security Plugin CVE-2024-52553Highorg.jenkins-ci.plugins:oic-auth: Session fixation vulnerability in Jenkins OpenId Connect Authentication PluginCVE-2024-47535Mediumio.netty:netty-common: Denial of Service attack on windows app using nettyCVE-2024-51135Highorg.powertac:server-interface: powertac-server XML External Entity vulnerabilityCVE-2024-52007Highca.uhn.hapi.fhir:org.hl7.fhir.dstu3: XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`CVE-2024-47072Highcom.thoughtworks.xstream:xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input streamCVE-2024-51504Highorg.apache.zookeeper:zookeeper: Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin ServerCVE-2023-1973Mediumio.undertow:undertow-core: Undertow Denial of Service vulnerabilityCVE-2023-1932Mediumorg.hibernate.validator:hibernate-validator: hibernate-validator Cross-site Scripting vulnerabilityCVE-2024-38286Highorg.apache.tomcat:tomcat-coyote: Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerabilityCVE-2024-51132Highca.uhn.hapi.fhir:org.hl7.fhir.convertors: HAPI FHIR XML External Entity (XXE) vulnerabilityGHSA-82J3-HF72-7X93Highcom.reposilite:reposilite-backend: Reposilite vulnerable to path traversal while serving javadoc expanded files (arbitrary file read) (`GHSL-2024-074`)CVE-2024-51127Highorg.hornetq:hornetq-core-client: hornetq vulnerable to file overwrite, sensitive information disclosureCVE-2024-23590Highorg.apache.kylin:kylin: Apache Kylin Session Fixation vulnerabilityCVE-2024-48307Highorg.jeecgframework.boot:jeecg-boot-parent: JeecgBoot SQL Injection vulnerabilityCVE-2024-43382Mediumnet.snowflake:snowflake-jdbc: Snowflake JDBC Security AdvisoryCVE-2024-45477Mediumorg.apache.nifi:nifi-web-ui: Apache NiFi Cross-site Scripting vulnerabilityCVE-2024-49771Mediumnet.sf.mpxj:mpxj: MPXJ has a Potential Path Traversal VulnerabilityCVE-2024-38821Criticalorg.springframework.security:spring-security-web: Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux ApplicationsCVE-2024-49760Highorg.openrefine:openrefine: OpenRefine has a path traversal in LoadLanguageCommandGHSA-3PG4-QWC8-426RHighorg.openrefine:openrefine: OpenRefine leaks Google API credentials in releasesGHSA-MPCW-3J5P-P99XMediumorg.openrefine.dependencies:butterfly: Butterfly's parseJSON, getJSON functions eval malicious input, leading to remote code execution (RCE)CVE-2024-47883Criticalorg.openrefine.dependencies:butterfly: Butterfly has path/URL confusion in resource handling leading to multiple weaknessesCVE-2024-47882Mediumorg.openrefine:openrefine: OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project

Stop the waste.
Protect your environment with Kodem.