Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-23818Mediumorg.geoserver:gs-wms: GeoServer's WMS OpenLayers Format vulnerable to Stored Cross-Site Scripting (XSS)CVE-2024-23643Mediumorg.geoserver:gs-gwc-rest: GeoServer's GWC Seed Form vulnerable to Stored Cross-Site Scripting (XSS)CVE-2024-23642Mediumorg.geoserver:gs-wms: GeoServer's Simple SVG Renderer vulnerable to Stored Cross-Site Scripting (XSS)CVE-2024-23640Mediumorg.geoserver:gs-main: GeoServer's Style Publisher vulnerable to Stored Cross-Site Scripting (XSS)CVE-2024-23634Mediumorg.geoserver:gs-restconfig: GeoServer Arbitrary file renaming vulnerability in REST Coverage/Data Store APICVE-2023-51445Mediumorg.geoserver:gs-restconfig: Stored Cross-Site Scripting (XSS) vulnerability in GeoServer's REST Resources APICVE-2023-51444Highorg.geoserver:gs-platform: Arbitrary file upload vulnerability in GeoServer's REST Coverage Store APICVE-2023-41877Highorg.geoserver:gs-main: GeoServer log file path traversal vulnerabilityCVE-2024-27439Mediumorg.apache.wicket:wicket: Cross-Site Request Forgery in Apache WicketCVE-2024-24683Mediumorg.apache.hop:hop: Improper Input Validation vulnerability in Apache Hop EngineCVE-2024-24042Highnet.devtech:arrp: Path traversal in flaskcode Devan-Kerman ARRPCVE-2024-22257Highorg.springframework.security:spring-security-core: Erroneous authentication pass in Spring SecurityCVE-2024-28128Mediumorg.fitnesse:fitnesse: FitNesse Cross-site Scripting vulnerabilityCVE-2024-28125Criticalorg.fitnesse:fitnesse: FitNesse allows execution of arbitrary OS commandsCVE-2024-22259Highorg.springframework:spring-web: Spring Framework URL Parsing with Host Validation VulnerabilityCVE-2024-28752Criticalorg.apache.cxf:cxf-rt-databinding-aegis: SSRF vulnerability using the Aegis DataBinding in Apache CXFCVE-2024-23944Mediumorg.apache.zookeeper:zookeeper: Apache ZooKeeper vulnerable to information disclosure in persistent watchers handlingCVE-2024-23672Mediumorg.apache.tomcat:tomcat-websocket: Denial of Service via incomplete cleanup vulnerability in Apache TomcatCVE-2024-24549Mediumorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requestsCVE-2024-1979Lowio.quarkus:quarkus-kubernetes-deployment: In Quarkus, git credentials could be inadvertently publishedCVE-2024-27894Highorg.apache.pulsar:pulsar-functions-worker: Apache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS ProxyingCVE-2024-27317Criticalorg.apache.pulsar:pulsar-functions-worker: Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File ModificationCVE-2024-27135Highorg.apache.pulsar:pulsar-functions-worker: Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code ExecutionCVE-2022-34321Highorg.apache.pulsar:pulsar-proxy: Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics EndpointCVE-2024-28098Mediumorg.apache.pulsar:pulsar-broker: Apache Pulsar: Improper Authorization For Topic-Level Policy Management

Stop the waste.
Protect your environment with Kodem.