Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-47881Highorg.openrefine:database: OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)CVE-2024-47880Highorg.openrefine:openrefine: OpenRefine has a reflected cross-site scripting vulnerability (XSS) from POST request in ExportRowsCommandCVE-2024-47879Highorg.openrefine:main: OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)CVE-2024-47878Highorg.openrefine:extensions: OpenRefine has a reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)CVE-2024-45031Mediumorg.apache.syncope.client:syncope-client-console: Apache Syncope: Stored XSS in Console and EnduserCVE-2024-26271Highcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account WidgetCVE-2024-38002Criticalcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Workflow Component Does Not Check User PermissionsCVE-2024-26273Highcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page EditorCVE-2024-26272Highcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page EditorCVE-2024-8980Criticalcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script ConsoleCVE-2024-38820Mediumorg.springframework:spring-context: Spring Framework DataBinder Case Sensitive Match ExceptionCVE-2024-49580Mediumio.ktor:ktor-client-core-jvm: JetBrains Ktor information disclosureCVE-2024-45217Highorg.apache.solr:solr: Insecure Default Initialization of Resource vulnerability in Apache SolrCVE-2024-45216Criticalorg.apache.solr:solr: Improper Authentication vulnerability in Apache SolrCVE-2024-47876Highorg.sakaiproject.kernel:sakai-kernel-impl: SAK-50571 Sakai Kernel users created with type roleview can login as a normal userCVE-2024-6763Mediumorg.eclipse.jetty:jetty-http: Eclipse Jetty URI parsing of invalid authorityCVE-2024-8184Mediumorg.eclipse.jetty:jetty-server: Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacksCVE-2024-6762Loworg.eclipse.jetty:jetty-servlets: Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacksCVE-2024-7318Mediumorg.keycloak:keycloak-core: Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverityCVE-2024-7341Highorg.keycloak:keycloak-services: Keycloak has session fixation in Elytron SAML adaptersCVE-2024-8883Mediumorg.keycloak:keycloak-services: Keycloak has Vulnerable Redirect URI Validation Results in Open RedirectCVE-2024-8698Highorg.keycloak:keycloak-saml-core: Improper Verification of SAML Responses Leading to Privilege Escalation in KeycloakCVE-2023-50780Highorg.apache.activemq:artemis-cli: Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeansCVE-2024-9823Mediumorg.eclipse.jetty.ee10:jetty-ee10-servlets: Eclipse Jetty has a denial of service vulnerability on DosFilterCVE-2023-25581Criticalorg.pac4j:pac4j-core: pac4j-core affected by a Java deserialization vulnerability

Stop the waste.
Protect your environment with Kodem.