Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-43401Criticalorg.xwiki.platform:xwiki-platform-web-templates: In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit themCVE-2024-43400Criticalorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform allows XSS through XClass name in string propertiesCVE-2024-44076Highio.github.microcks:microcks-app: Microcks's POST /api/import and POST /api/export endpoints allow non-administrator accessCVE-2024-42850Loworg.silverpeas.core:silverpeas-core: Silverpeas vulnerable to password complexity rule bypassCVE-2024-42681Highcom.xuxueli:xxl-job-core: Improper Preservation of Permissions in xxl-jobCVE-2024-41909Highorg.apache.sshd:sshd-common: Apache MINA SSHD: integrity check bypassCVE-2024-29831Highorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler: RCE by arbitrary js executionCVE-2024-30188Highorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler: Resource File Read And Write VulnerabilityCVE-2024-42468Mediumorg.openhab.ui.bundles:org.openhab.ui.cometvisu: CometVisu Backend for openHAB has a path traversal vulnerabilityCVE-2024-42469Criticalorg.openhab.ui.bundles:org.openhab.ui.cometvisu: CometVisu Backend for openHAB affected by RCE through path traversalCVE-2024-42470Mediumorg.openhab.ui.bundles:org.openhab.ui.cometvisu: CometVisu Backend for openHAB has a sensitive information disclosure vulnerabilityCVE-2024-42467Highorg.openhab.ui.bundles:org.openhab.ui.cometvisu: CometVisu Backend for openHAB affected by SSRF/XSSCVE-2024-43045Mediumorg.jenkins-ci.main:jenkins-core: Jenkins does not perform a permission check in an HTTP endpointCVE-2024-43044Highorg.jenkins-ci.main:remoting: Jenkins Remoting library arbitrary file read vulnerabilityCVE-2023-45146Criticalcom.xuxueli:xxl-rpc-core: XXL-RPC Deserialization of Untrusted Data vulnerabilityCVE-2023-42809Criticalorg.redisson:redisson: Redisson vulnerable to Deserialization of Untrusted DataCVE-2023-28857Mediumorg.apereo.cas:cas-server-support-x509-core: Apereo CAS vulnerable to credential leaks for LDAP authenticationCVE-2022-23554Mediumus.springett:alpine: Alpine allows Authentication Filter bypassCVE-2022-23553Highus.springett:alpine: Alpine allows URL access filter bypassCVE-2024-36116Highcom.reposilite:reposilite-backend: Path traversal in Reposilite javadoc file expansion (arbitrary file creation/overwrite) (`GHSL-2024-073`)CVE-2024-36115Highcom.reposilite:reposilite-backend: Reposilite artifacts vulnerable to Stored Cross-site ScriptingCVE-2024-27181Highorg.apache.linkis:linkis: Apache Linkis vulnerable to privilege escalationCVE-2024-27182Highorg.apache.linkis:linkis: Apache Linkis arbitrary file deletion vulnerabilityCVE-2024-36268Highorg.apache.inlong:tubemq-core: Apache Inlong Code Injection vulnerabilityCVE-2024-41948Mediumorg.biscuitsec:biscuit: biscuit-java vulnerable to public key confusion in third party block

Stop the waste.
Protect your environment with Kodem.