Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-23444Mediumorg.elasticsearch:elasticsearch: Elasticsearch stores private key on disk unencryptedCVE-2024-41947Criticalorg.xwiki.platform:xwiki-platform-web-templates: XWiki Platform vulnerable to Cross-Site Scripting (XSS) through conflict resolutionCVE-2024-37901Criticalorg.xwiki.platform:xwiki-platform-search-ui: XWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheetCVE-2024-37900Highorg.xwiki.platform:xwiki-platform-web-war: XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploaderCVE-2024-37898Mediumorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform vulnerable to document deletion and overwrite from editCVE-2023-48396Highorg.apache.seatunnel:seatunnel-web: Apache SeaTunnel Web Authentication vulnerabilityCVE-2024-40094Highcom.graphql-java:graphql-java: GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of serviceCVE-2023-49921Mediumorg.elasticsearch:elasticsearch: Elasticsearch Insertion of Sensitive Information into Log FileCVE-2024-41667Highorg.openidentityplatform.openam:openam-oauth2: OpenAM FreeMarker template injectionCVE-2024-37084Criticalorg.springframework.cloud:spring-cloud-skipper: Remote code execution in Spring Cloud Data FlowCVE-2024-39676Highorg.apache.pinot:pinot-controller: Apache Pinot: Unauthorized endpoint exposed sensitive informationCVE-2023-48362Highorg.apache.drill.exec:drill-java-exec: XML External Entity Reference (XXE) in the XML Format Plugin in Apache DrillGHSA-CRJG-W57M-RQQFHighdnsjava:dnsjava: DNSJava vulnerable to KeyTrap - Denial-of-Service Algorithmic Complexity AttacksGHSA-MMWX-RJ87-VFGRHighdnsjava:dnsjava: DNSJava affected by KeyTrap - NSEC3 closest encloser proof can exhaust CPU resourcesCVE-2024-25638Highdnsjava:dnsjava: DNSJava DNSSEC BypassCVE-2024-38503Highorg.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui: Apache Syncope Improper Input Validation vulnerabilityCVE-2024-23321Mediumorg.apache.rocketmq:rocketmq-all: Apache RocketMQ Vulnerable to Unauthorized Exposure of Sensitive DataCVE-2024-6960Highai.h2o:h2o-core: H2O vulnerable to Deserialization of Untrusted DataCVE-2024-29736Highorg.apache.cxf:cxf-rt-rs-service-description: Apache CXF: SSRF vulnerability via WADL stylesheet parameterCVE-2024-41172Mediumorg.apache.cxf:cxf-rt-transports-http: Apache CXF allows unrestricted memory consumption in CXF HTTP clientsCVE-2024-32007Mediumorg.apache.cxf:cxf-rt-rs-security-jose: Apache CXF Denial of Service vulnerability in JOSECVE-2024-40642Highio.netty.incubator:netty-incubator-codec-bhttp: Absent Input Validation in BinaryHttpParserCVE-2024-39900Mediumorg.opensearch.plugin:opensearch-reports-scheduler: The OpenSearch reporting plugin improperly controls tenancy access to reporting resourcesCVE-2024-29178Highorg.apache.streampark:streampark: Apache StreamPark: FreeMarker SSTI RCE VulnerabilityCVE-2024-29120Mediumorg.apache.streampark:streampark: Apache StreamPark: Information leakage vulnerability

Stop the waste.
Protect your environment with Kodem.