Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-4629Mediumorg.keycloak:keycloak-services: Keycloak Services has a potential bypass of brute force protectionCVE-2024-45537Loworg.apache.druid:druid: Apache Druid: Users can provide MySQL JDBC properties not on allow listCVE-2024-45384Loworg.apache.druid.extensions:druid-pac4j: druid-pac4j, Apache Druid extension, has Padding Oracle vulnerabilityGHSA-2GH6-WC3M-G37FCriticalpl.allegro.tech.hermes:hermes-management: hermes-management is vulnerable to RCE due to Apache commons-jxpathCVE-2024-46943Mediumorg.opendaylight.aaa:aaa-artifacts: OpenDaylight Authentication, Authorization and Accounting (AAA) peer impersonation vulnerabilityCVE-2024-46942Highorg.opendaylight.mdsal:mdsal-artifacts: OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) allows follower controller to set up flow entriesCVE-2024-22399Criticalorg.apache.seata:seata-core: Apache Seata Deserialization of Untrusted Data vulnerabilityCVE-2024-38816Highorg.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworksCVE-2024-8642Mediumorg.eclipse.edc:transfer-data-plane: Eclipse Dataspace Components's ConsumerPullTransferTokenValidationApiController doesn't check for token validitCVE-2024-8646Mediumorg.glassfish.main.web:web-core: Eclipse Glassfish URL redirection vulnerabilityCVE-2023-6841Highorg.keycloak:keycloak-core: Keycloak Denial of Service vulnerabilityCVE-2024-45591Mediumorg.xwiki.platform:xwiki-platform-rest-server: XWiki Platform document history including authors of any page exposed to unauthorized actorsCVE-2024-7260Mediumorg.keycloak:keycloak-core: Keycloak Open Redirect vulnerabilityCVE-2024-45294Highca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may: XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`CVE-2024-45758Criticalai.h2o:h2o-core: H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URLCVE-2024-8391Mediumio.vertx:vertx-grpc-server: Vertx gRPC server does not limit the maximum message sizeCVE-2024-8285Mediumio.kroxylicious:kroxylicious-runtime: Missing hostname validation in KroxyliciousCVE-2024-38807Highorg.springframework.boot:spring-boot-loader: Signature forgery in Spring Boot's LoaderCVE-2024-7885Highio.undertow:undertow-core: Undertow vulnerable to Race ConditionCVE-2023-49198Highorg.apache.seatunnel:seatunnel: Apache SeaTunnel SQL Injection vulnerabilityCVE-2024-22281Highorg.apache.helix:helix: Apache Helix Front (UI) component contained a hard-coded secretCVE-2024-43397Mediumcom.ctrip.framework.apollo:apollo: apollo-portal has potential unauthorized access issueCVE-2024-43202Criticalorg.apache.dolphinscheduler:dolphinscheduler-task-api: Apache Dolphinscheduler Code Injection vulnerabilityCVE-2024-38808Mediumorg.springframework:spring-expression: Spring Framework vulnerable to Denial of ServiceCVE-2024-38810Mediumorg.springframework.security:spring-security-core: Spring Security Missing Authorization vulnerability

Stop the waste.
Protect your environment with Kodem.