Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-31862Mediumorg.apache.zeppelin:zeppelin-server: Apache Zeppelin: Denial of service with invalid notebook nameCVE-2024-3046Highorg.eclipse.kura:org.eclipse.kura.web2: Eclipse Kura LogServlet vulnerabilityCVE-2022-47894Mediumorg.apache.zeppelin:sap: Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXECVE-2021-28656Mediumorg.apache.zeppelin:zeppelin-web: Apache Zeppelin CSRF vulnerability in the Credentials pageCVE-2024-31860Mediumorg.apache.zeppelin:zeppelin-server: Apache Zeppelin Path Traversal vulnerabilityCVE-2024-1233Highorg.wildfly.security:wildfly-elytron-realm-token: WildFly Elytron: SSRF security issueCVE-2024-3366Lowcom.xuxueli:xxl-job-core: Xuxueli xxl-job template injection vulnerabilityCVE-2024-2700Highio.quarkus:quarkus-core: quarkus-core leaks local environment variables from Quarkus namespace during application's buildCVE-2024-29834Mediumorg.apache.pulsar:pulsar-broker: Apache Pulsar: Improper Authorization For Namespace and Topic Management EndpointsCVE-2024-1300Mediumio.vertx:vertx-core: Eclipse Vert.x vulnerable to a memory leak in TCP serversCVE-2024-27609Mediumorg.bonitasoft.console:bonita-web-server: Bonita cross-site scripting vulnerabilityCVE-2024-23449Mediumorg.elasticsearch:elasticsearch: Elasticsearch Uncaught Exception leading to crashCVE-2024-23451Mediumorg.elasticsearch:elasticsearch: Elasticsearch Incorrect Authorization vulnerabilityCVE-2024-23450Mediumorg.elasticsearch:elasticsearch: Elasticsearch Uncontrolled Resource Consumption vulnerabilityCVE-2024-1023Mediumio.vertx:vertx-core: Eclipse Vert.x memory leakCVE-2024-25421Highorg.igniterealtime.openfire:xmppserver: Ignite Realtime Openfire privilege escalation vulnerabilityCVE-2024-25420Highorg.igniterealtime.openfire:xmppserver: Ignite Realtime Openfire privilege escalation vulnerabilityCVE-2024-29025Mediumio.netty:netty-codec-http: Netty's HttpPostRequestDecoder can OOMCVE-2023-5685Highorg.jboss.xnio:xnio-api: XNIO denial of service vulnerabilityCVE-2024-29131Mediumorg.apache.commons:commons-configuration2: Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()CVE-2024-29133Mediumorg.apache.commons:commons-configuration2: Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object treeCVE-2022-4963Mediumorg.folio:spring-module-core: SQL injection in Folio Spring Module CoreCVE-2024-22258Mediumorg.springframework.security:spring-security-oauth2-authorization-server: Improper Authentication in Spring Authorization ServerCVE-2024-23821Mediumorg.geoserver:gs-gwc: GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS)CVE-2024-23819Mediumorg.geoserver.extension:gs-mapml: GeoServer's MapML HTML Page vulnerable to Stored Cross-Site Scripting (XSS)

Stop the waste.
Protect your environment with Kodem.