Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-7272Criticalorg.eclipse.parsson:parsson: Eclipse Parsson stack overflow when parsing deeply nested inputCVE-2024-31411Highorg.apache.streampipes:streampipes-parent: Apache StreamPipes has potential remote code execution (RCE) via file uploadCVE-2023-52291Mediumorg.apache.streampark:streampark: Apache StreamPark: Unchecked maven build params could trigger remote command executionCVE-2024-31979Mediumorg.apache.streampipes:streampipes-parent: Apache StreamPipes has possibility of SSRF in pipeline element installation processCVE-2024-30471Mediumorg.apache.streampipes:streampipes-parent: Apache StreamPipes potentially allows creation of multiple identical accountsCVE-2024-29737Mediumorg.apache.streampark:streampark: Apache StreamPark: maven build params could trigger remote command executionCVE-2023-49566Highorg.apache.linkis:linkis-datasource: Apache Linkis DataSource's JDBC Datasource Module with DB2 has JNDI Injection vulnerabilityCVE-2023-46801Highorg.apache.linkis:linkis-datasource: Apache Linkis DataSource remote code execution vulnerabilityCVE-2023-41916Highorg.apache.linkis:linkis-datasource: Apache Linkis DataSource allows arbitrary file readingCVE-2024-36522Highorg.apache.wicket:wicket-util: Apache Wicket: Remote code execution via XSLT injectionCVE-2024-39901Loworg.opensearch.plugin:opensearch-observability: OpenSearch Observability does not properly restrict access to private tenant resourcesCVE-2024-39031Mediumorg.silverpeas.core:silverpeas-core-rs: Silverpeas Core Cross-site Scripting vulnerabilityCVE-2024-22271Highorg.springframework.cloud:spring-cloud-function-context: Spring Cloud Function Framework vulnerable to Denial of ServiceCVE-2024-3653Mediumio.undertow:undertow-core: Undertow Missing Release of Memory after Effective Lifetime vulnerabilityCVE-2024-5971Highio.undertow:undertow-core: Undertow Denial of Service vulnerabilityCVE-2024-37389Mediumorg.apache.nifi:nifi-web-ui: Apache NiFi vulnerable to Cross-site ScriptingCVE-2024-34750Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat - Denial of ServiceCVE-2024-36401Criticalorg.geoserver.web:gs-web-app: Remote Code Execution (RCE) vulnerability in geoserverCVE-2024-24749Highorg.geoserver.web:gs-web-app: Classpath resource disclosure in GWC Web Resource API on Windows / TomcatCVE-2024-34696Mediumorg.geoserver.web:gs-web-app: GeoServer's Server Status shows sensitive environmental variables and Java propertiesCVE-2024-39458Loworg.jenkins-ci.plugins:structs: Exposure of secrets through system log in Jenkins Structs PluginCVE-2024-39459Mediumorg.jenkins-ci.plugins:plain-credentials: Secret file credentials stored unencrypted in rare cases by Plain Credentials Plugin CVE-2024-39460Mediumorg.jenkins-ci.plugins:cloudbees-bitbucket-branch-source: Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin CVE-2024-38364Loworg.dspace:dspace-server-webapp: DSpace Cross Site Scripting (XSS) via a deposited HTML/XML documentCVE-2024-38374Highorg.cyclonedx:cyclonedx-core-java: Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java

Stop the waste.
Protect your environment with Kodem.