Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-40191Criticalcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to reflected Cross-site ScriptingCVE-2021-29050Highcom.liferay.portal:com.liferay.portal.impl: Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use PageCVE-2021-29038Mediumcom.liferay.portal:portal-impl: Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder AnswersCVE-2024-26140Mediumcom.yetanalytics:lrs: Cross-site Scripting Vulnerability in Statement BrowserCVE-2024-23114Highorg.apache.camel:camel-cassandraql: Deserialization of Untrusted Data in Apache Camel CassandraQLCVE-2024-22369Highorg.apache.camel:camel-sql: Deserialization of Untrusted Data in Apache Camel SQLCVE-2024-26270Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP vulnerable to theft of hashed passwordCVE-2024-26268Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP User Enumeration VulnerabilityCVE-2024-26267Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP HTTP Header Can Expose VersionsCVE-2024-26265Mediumcom.liferay.portal:release.portal.bom: Liferay Portal vulnerable to Denial of ServiceCVE-2024-25610Criticalcom.liferay.portal:release.portal.bom: Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)CVE-2024-25609Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Two Forward SlashesCVE-2023-51770Highorg.apache.dolphinscheduler:dolphinscheduler: Arbitrary File Read Vulnerability in Apache DolphinschedulerCVE-2023-49250Highorg.apache.dolphinscheduler:dolphinscheduler: Improper Certificate Validation in Apache DolphinSchedulerCVE-2023-50270Mediumorg.apache.dolphinscheduler:dolphinscheduler: Session Fixation Apache DolphinSchedulerCVE-2024-25607Highcom.liferay.portal:release.dxp.bom: Liferay Portal defaults to a low work factor for the default password hashing algorithmCVE-2024-25608Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement CharacterCVE-2023-49109Criticalorg.apache.dolphinscheduler:dolphinscheduler: Remote Code Execution in Apache DolphinschedulerCVE-2024-25606Highcom.liferay.portal:com.liferay.util.java: Liferay Portal has an XXE vulnerability in Java2WsddTask._formatCVE-2024-25605Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or APICVE-2024-25604Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit PermissionsCVE-2024-25150Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control PanelCVE-2024-25149Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site OptionsCVE-2023-44308Mediumcom.liferay:com.liferay.adaptive.media.web: Liferay Vulnerable to Open Redirect via Adaptive Media Administration PageCVE-2024-22234Highorg.springframework.security:spring-security-core: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated

Stop the waste.
Protect your environment with Kodem.