Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-34147Loworg.jenkins-ci.plugins:telegrambot: Jenkins Telegram Bot Plugin stores the Telegram Bot token in plaintextCVE-2024-34146Mediumorg.jenkins-ci.plugins:git-server: Jenkins Git server Plugin does not perform a permission checkCVE-2024-34145Highorg.jenkins-ci.plugins:script-security: Jenkins Script Security Plugin sandbox bypass vulnerabilityCVE-2024-34144Highorg.jenkins-ci.plugins:script-security: Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodiesCVE-2024-32114Highorg.apache.activemq:apache-activemq: Apache ActiveMQ's default configuration doesn't secure the API web contextCVE-2024-31573Loworg.xmlunit:xmlunit-core: XMLUnit for Java has Insecure Defaults when Processing XSLT StylesheetsCVE-2024-1102Mediumorg.jberet:jberet-core: Jberet: jberet-core logging database credentialsCVE-2023-5675Mediumio.quarkus:quarkus-resteasy-reactive-common-deployment: Quarkus: authorization flaw in quarkus resteasy reactive and classicCVE-2024-1726Mediumio.quarkus.resteasy.reactive:resteasy-reactive: Quarkus: security checks in resteasy reactive may trigger a denial of serviceCVE-2024-28848Highorg.open-metadata:openmetadata-service: OpenMetadata vulnerable to a SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` (`GHSL-2023-236`)CVE-2024-28847Highorg.open-metadata:openmetadata-service: OpenMetadata vulnerable to a SpEL Injection in `PUT /api/v1/events/subscriptions` (`GHSL-2023-251`)CVE-2024-28253Criticalorg.open-metadata:openmetadata-service: OpenMetadata vulnerable to SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)GHSA-HVP5-5X4F-33FQLowio.github.skylot:jadx-core: JADX file override vulnerabilityCVE-2024-32656Highio.antmedia:ant-media-server: Ant Media Server vulnerable to a local privilege escalationCVE-2024-27349Highorg.apache.hugegraph:hugegraph-api: Apache HugeGraph-Server: Bypass whitelist in Auth modeCVE-2024-27348Criticalorg.apache.hugegraph:hugegraph-api: Apache HugeGraph-Server: Command execution in gremlinCVE-2024-27347Mediumorg.apache.hugegraph:hugegraph-hubble: Apache HugeGraph-Hubble: SSRF in Hubble connection pageCVE-2023-0657Loworg.keycloak:keycloak-services: Keycloak vulnerable to impersonation via logout token exchangeCVE-2023-6787Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to session hijacking via re-authenticationCVE-2024-1132Highorg.keycloak:keycloak-services: Keycloak path traversal vulnerability in redirection validationCVE-2024-1249Highorg.keycloak:keycloak-services: Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoSCVE-2023-6484Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to log Injection during WebAuthn authentication or registrationCVE-2023-6544Mediumorg.keycloak:keycloak-services: Keycloak Authorization Bypass vulnerabilityCVE-2023-6717Mediumorg.keycloak:keycloak-services: Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flowCVE-2023-3597Mediumorg.keycloak:keycloak-services: Keycloak secondary factor bypass in step-up authentication

Stop the waste.
Protect your environment with Kodem.