Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-45320Mediumcom.liferay.portal:release.portal.bom: Privilege escalation in Liferay PortalCVE-2023-5190Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region PageCVE-2024-1635Highio.undertow:undertow-core: Undertow Uncontrolled Resource Consumption VulnerabilityCVE-2024-26308Mediumorg.apache.commons:commons-compress: Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 fileCVE-2024-25710Mediumorg.apache.commons:commons-compress: Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP fileCVE-2024-20925Loworg.openjfx:javafx-media: Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX projectCVE-2023-45860Highcom.hazelcast:hazelcast: Hazelcast Platform permission checking in CSV File Source connectorCVE-2024-25125Mediumio.digdag:digdag-server: Absolute path traversal vulnerability in digdag serverCVE-2024-1459Mediumio.undertow:undertow-core: Undertow Path Traversal vulnerabilityCVE-2024-23833Highorg.openrefine:database: OpenRefine JDBC Attack VulnerabilityCVE-2023-52428Highcom.nimbusds:nimbus-jose-jwt: Denial of Service in Connect2id Nimbus JOSE+JWTCVE-2024-21490Highangular: angular vulnerable to super-linear runtime due to backtrackingCVE-2023-50386Highorg.apache.solr:solr-core: Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets CVE-2023-50292Loworg.apache.solr:solr-core: Apache Solr Schema Designer blindly "trusts" all configsetsCVE-2023-50291Highorg.apache.solr:solr-core: Apache Solr can leak certain passwords due to System Property redaction logic inconsistenciesCVE-2023-50298Mediumorg.apache.solr:solr-solrj-streaming: Apache Solr's Streaming Expressions allow users to extract data from other Solr CloudsCVE-2024-23639Mediumio.micronaut:micronaut-http-server: Micronaut management endpoints vulnerable to drive-by localhost attackCVE-2024-24113Highcom.xuxueli:xxl-job: XXL-JOB vulnerable to Server-Side Request ForgeryCVE-2024-25148Highcom.liferay.portal:release.portal.bom: Liferay Portal vulnerable to user impersonationCVE-2024-25146Mediumcom.liferay.portal:release.portal.bom: Liferay Portal allows attackers to discover the existence of sitesCVE-2024-25144Mediumcom.liferay.portal:release.portal.bom: Liferay Portal denial-of-service vulnerabilityCVE-2023-47798Mediumcom.liferay.portal:release.portal.bom: Liferay Portal's account lockout does not invalidate existing user sessionsCVE-2024-24823Mediumorg.graylog2:graylog2-server: Graylog session fixation vulnerability through cookie injectionCVE-2024-24824Highorg.graylog2:graylog2-server: Graylog vulnerable to instantiation of arbitrary classes triggered by API requestCVE-2024-25143Highcom.liferay.portal:release.portal.bom: Liferay Portal denial of service (memory consumption)

Stop the waste.
Protect your environment with Kodem.