Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-36114Highio.airlift:aircompressor: Decompressors can crash the JVM and leak memory content in AircompressorCVE-2024-5520Mediumorg.opencms:opencms-core: OpenCMS Cross-Site Scripting vulnerabilityCVE-2024-35219Highorg.openapitools:openapi-generator-online: OpenAPI Generator Online - Arbitrary File Read/DeleteCVE-2023-46442Highorg.soot-oss:soot: Soot Infinite Loop vulnerabilityCVE-2024-22588Mediumtech.kwik:kwik: Kwik does not discard unused encryption keysCVE-2024-5273Loworg.jenkins-ci.plugins:report-info: Jenkins Report Info Plugin Path Traversal vulnerabilityCVE-2024-5165Mediumorg.eclipse.ditto:ditto: Eclipse Ditto vulnerable to Cross-site ScriptingCVE-2024-29392Mediumorg.silverpeas.core:silverpeas-core: Silverpeas Core vulnerable to Cross Site ScriptingCVE-2024-28109Highorg.verapdf:core: veraPDF has potential XSLT injection vulnerability when using policy filesCVE-2024-28087Mediumorg.bonitasoft.engine:bonita-server: Bonitasoft Runtime Community edition's contains an insecure direct object references vulnerabilityCVE-2024-32888Criticalcom.amazon.redshift:redshift-jdbc42: Amazon JDBC Driver for Redshift SQL Injection via line comment generationCVE-2024-3462Lowio.antmedia:ant-media-server: Ant Media Server does not properly authorize non-administrative API callsCVE-2024-34365Criticalorg.apache.karaf:cave: Apache Karaf Cave: Cave SSRF and arbitrary file access CVE-2024-30171Mediumorg.bouncycastle:bctls-fips: Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")CVE-2024-30172MediumBouncyCastle: Bouncy Castle crafted signature and public key can be used to trigger an infinite loopCVE-2024-29857Mediumorg.bouncycastle:bcprov-jdk18on: Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.CVE-2024-4701Criticalcom.netflix.genie:genie-web: Genie Path Traversal vulnerability via File UploadsCVE-2024-26579Criticalorg.apache.inlong:manager-pojo: Apache Inlong Deserialization of Untrusted Data vulnerabilityCVE-2024-34517Mediumorg.neo4j:neo4j-cypher: Neo4j Cypher component mishandles IMMUTABLE privilegesCVE-2024-33748Mediumnet.mingsoft:ms-basic: MS Basic Cross-site Scripting vulnerabilityCVE-2024-4536Mediumorg.eclipse.edc:connector-core: Eclipse Dataspace Components vulnerable to OAuth2 client secret disclosureCVE-2024-34447Mediumorg.bouncycastle:bcprov-jdk18on: Bouncy Castle Java Cryptography API vulnerable to DNS poisoningCVE-2023-35701Mediumorg.apache.hive:hive-jdbc: Apache Hive Code Injection vulnerabilityCVE-2024-4029Mediumorg.wildfly:wildfly-domain-http: Wildfly vulnerable to denial of serviceCVE-2024-34148Mediumorg.jenkins-ci.plugins:partial-release-manager: Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721

Stop the waste.
Protect your environment with Kodem.