Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-34055Mediumorg.springframework.boot:spring-boot-actuator: Spring Boot Actuator denial of service vulnerabilityCVE-2023-34053Highorg.springframework:spring-webmvc: Spring Framework vulnerable to denial of serviceCVE-2023-34054Highio.projectreactor.netty:reactor-netty-core: Reactor Netty HTTP Server denial of service vulnerabilityCVE-2023-49145Highorg.apache.nifi:nifi-jolt-transform-json-ui: Improper Neutralization of Input in Advanced User Interface for JoltGHSA-R68H-JHHJ-9JVMMediumorg.owasp.esapi:esapi: Validator.isValidSafeHTML is being deprecated and will be deleted from org.owasp.esapi:esapi in 1 yearCVE-2023-49068Mediumorg.apache.dolphinscheduler:dolphinscheduler-api: Apache DolphinScheduler Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityCVE-2023-48796Highorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler sensitive information disclosureCVE-2023-33202Mediumorg.bouncycastle:bcprov-jdk18on: Bouncy Castle Denial of Service (DoS)CVE-2023-43123Mediumorg.apache.storm:storm-core: Apache Storm Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files CVE-2023-47467Mediumorg.jeecgframework.boot:jeecg-boot-common: Directory Traversal in jeecg-bootCVE-2023-46673Mediumorg.elasticsearch:elasticsearch: Elasticsearch Improper Handling of Exceptional ConditionsCVE-2021-37942Highco.elastic.apm:apm-agent-parent: APM Java Agent Local Privilege Escalation issueCVE-2023-48293Highorg.xwiki.contrib:xwiki-application-admintools: Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queriesCVE-2023-48292Criticalorg.xwiki.contrib:xwiki-application-admintools: Run Shell Command allows Cross-Site Request ForgeryCVE-2023-48241Highorg.xwiki.platform:xwiki-platform-search-solr-query: Whole content of all documents of all wikis exposed to anybody with view right on Solr suggest serviceCVE-2023-48240Criticalorg.xwiki.platform:xwiki-platform-diff-xml: Cookies are sent to external images in rendered diff (and server side request forgery)CVE-2022-46337Criticalorg.apache.derby:derby: Apache Derby: LDAP injection vulnerability in authenticatorCVE-2023-40816Mediumorg.opencrx:opencrx-core-models: Cross-site Scripting in OpenCRXCVE-2023-40817Mediumorg.opencrx:opencrx-core-models: Cross-site Scripting in OpenCRXCVE-2023-40814Mediumorg.opencrx:opencrx-core-models: Cross-site Scripting in OpenCRXCVE-2023-40815Mediumorg.opencrx:opencrx-core-models: Cross-site Scripting in OpenCRXCVE-2023-40813Mediumorg.opencrx:opencrx-core-models: Cross-site Scripting in OpenCRXCVE-2023-40812Mediumorg.opencrx:opencrx-core-models: Cross-site Scripting in OpenCRXCVE-2023-40810Mediumorg.opencrx:opencrx-core-models: Cross-site Scripting in OpenCRXCVE-2023-40809Mediumorg.opencrx:opencrx-core-models: Cross-site Scripting in OpenCRX

Stop the waste.
Protect your environment with Kodem.