Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-50578Highnet.mingsoft:ms-mcms: Mingsoft MCMS SQL injectionCVE-2023-41544Criticalorg.jeecgframework.boot:jeecg-boot-common: JeecgBoot server-side template injectionCVE-2023-41543Criticalorg.jeecgframework.boot:jeecg-boot-common: Jeecg Boot SQL InjectionCVE-2023-41542Criticalorg.jeecgframework.boot:jeecg-boot-common: Jeecg Boot SQL injection vulnerabilityCVE-2023-3628Highorg.infinispan:infinispan-server-rest: Infinispan REST Server's bulk read endpoints do not properly evaluate user permissionsCVE-2023-3629Highorg.infinispan:infinispan-server-rest: Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissionsCVE-2023-50571Highorg.jeasy:easy-rules-mvel: easy-rules-mvel vulnerable to remote code executionCVE-2023-50572Mediumorg.jline:jline-parent: JLine vulnerable to out of memory errorCVE-2023-7148Mediumml.shifu:shifu: ShifuML shifu code injection vulnerabilityCVE-2023-5236Highorg.infinispan.protostream:protostream: Infinispan circular object references causes out of memory errorsCVE-2023-5384Mediumorg.infinispan:infinispan-core: Infinispan caches credentials in clear textCVE-2023-51080Highcn.hutool:hutool-core: hutool-core was discovered to contain a stack overflow via NumberUtil.toBigDecimal methodCVE-2023-51079Mediumorg.mvel:mvel2: mvel2 TimeOut error exists in the ParseTools.subCompileExpression methodCVE-2023-51084Criticalcom.github:hyavijava: hyavijava stack overflow vulnerabilityCVE-2023-51075Highcn.hutool:hutool-core: hutool-core discovered to contain an infinite loop in the StrSplitter.splitByRegex functionCVE-2023-51074Mediumcom.jayway.jsonpath:json-path: json-path Out-of-bounds Write vulnerabilityCVE-2023-27150Mediumorg.opencrx:opencrx-core: OpenCRX Cross-site Scripting vulnerabilityCVE-2023-6911Mediumorg.wso2.carbon.registry:carbon-registry: WSO2 Registry Stored Cross Site Scripting (XSS) vulnerabilityCVE-2023-6291Highorg.keycloak:keycloak-services: The redirect_uri validation logic allows for bypassing explicitly allowed hosts that would otherwise be restrictedCVE-2023-51656Criticalorg.apache.iotdb:iotdb-parent: Apache IoTDB: Unsafe deserialize map in Sync ToolCVE-2023-46131Mediumorg.grails:grails-databinding: Grails data binding causes JVM crash and/or other denial of serviceCVE-2023-37544Highorg.apache.pulsar:pulsar-websocket: Apache Pulsar WebSocket Proxy contains an Improper Authentication vulnerabilityCVE-2023-50732Highorg.xwiki.platform:xwiki-platform-index-tree-macro: Velocity execution without script right through tree macroCVE-2023-50730Highorg.typelevel:grackle-core_2.13: Grackle has StackOverflowError in GraphQL query processingCVE-2023-6134Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri

Stop the waste.
Protect your environment with Kodem.