Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-45859Highcom.hazelcast:hazelcast: Missing permission checks on Hazelcast client protocolCVE-2024-21742Mediumorg.apache.james:apache-mime4j-core: Apache James MIME4J improper input validation vulnerabilityCVE-2023-50380Mediumorg.apache.ambari.contrib.views:wfmanager: Apache Ambari XML External Entity injectionCVE-2023-51747Highorg.apache.james:james-server: SMTP smuggling in Apache JamesCVE-2023-50379Highorg.apache.ambari.contrib.views:ambari-contrib-views: Apache Ambari: authenticated users could perform command injection to perform RCECVE-2023-51518Criticalorg.apache.james:james-server: Apache James server: Privilege escalation via JMX pre-authentication deserializationCVE-2024-22201Highorg.eclipse.jetty.http2:http2-common: Connection leaking on idle timeout when TCP congestedGHSA-HX5Q-V6PJ-533RCriticalcom.linecorp.centraldogma:centraldogma-server-auth-saml: SAML authentication bypass due to missing validation on unsigned SAML messagesCVE-2024-1735Criticalcom.linecorp.armeria:armeria-saml: Armeria SAML authentication bypass due to missing validation on unsigned SAML messagesCVE-2024-22371Loworg.apache.camel:camel-core: Apache Camel data exposure vulnerabilityCVE-2024-23320Highorg.apache.dolphinscheduler:dolphinscheduler-master: Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated usersCVE-2024-22243Highorg.springframework:spring-web: Spring Web vulnerable to Open Redirect or Server Side Request ForgeryCVE-2024-1597Criticalorg.postgresql:postgresql: org.postgresql:postgresql vulnerable to SQL Injection via line comment generationCVE-2024-26138Mediumcom.xwiki.licensing:application-licensing-licensor-ui: XWiki extension license information is public, exposing instance id and license holder detailsCVE-2023-47795Criticalcom.liferay.portal:release.portal.bom: Liferay Portal Document and Media widget and Liferay DXP vulnerable to stored Cross-site ScriptingCVE-2024-25151Mediumcom.liferay.portal:release.portal.bom: Liferay Portal Calendar module and Liferay DXP vulnerable to Cross-site Scripting, content spoofingCVE-2024-26269Criticalcom.liferay.portal:release.portal.bom: Liferay Portal Frontend JS module's portlet.js and Liferay DXP vulnerable to Cross-site ScriptingCVE-2024-25603Criticalcom.liferay.portal:release.portal.bom: Liferay Portal's Dynamic Data Mapping module's DDMForm and Liferay DXP vulnerable to stored Cross-site ScriptingCVE-2024-26266Criticalcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to stored Cross-site ScriptingCVE-2024-25601Criticalcom.liferay.portal:release.portal.bom: Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site ScriptingCVE-2024-25152Criticalcom.liferay.portal:release.portal.bom: Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site ScriptingCVE-2024-25147Criticalcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to Cross-site ScriptingCVE-2024-25602Criticalcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP's Users Admin module vulnerable to stored Cross-site ScriptingCVE-2023-42498Criticalcom.liferay.portal:release.portal.bom: Liferay Portal Language Override edit screen and Liferay DXP vulnerable to reflected Cross-site ScriptingCVE-2023-42496Criticalcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting

Stop the waste.
Protect your environment with Kodem.