Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-47797Criticalcom.liferay.portal:release.portal.bom: Liferay Portal XSS with `p_l_back_url_title` on edit content pageCVE-2023-40314Mediumorg.opennms:opennms-webapp: OpenNMS Cross-site Scripting vulnerabilityCVE-2023-48222Highorg.rundeck:rundeck: Authenticated Rundeck users can view or delete jobs they do not have authorization for.CVE-2023-47112Mediumorg.rundeck:rundeckapp: Authenticated users can view job names and groups they do not have authorization to viewCVE-2023-6038Criticalai.h2o:h2o-core: H2O local file inclusion vulnerabilityCVE-2023-26031Highorg.apache.hadoop:hadoop-yarn-project: Apache Hadoop allows local user to gain root privilegesCVE-2023-48089Highcom.xuxueli:xxl-job-admin: xxl-job-admin vulnerable to Remote Code ExecutionCVE-2023-5245Highml.combust.mleap:mleap-runtime_2.12: Zip slip in mleapCVE-2023-48088Mediumcom.xuxueli:xxl-job-admin: xxl-job-admin vulnerable to Cross Site ScriptingCVE-2023-5720Highio.quarkus:quarkus-project: Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remainCVE-2023-48087Mediumcom.xuxueli:xxl-job-admin: xxl-job-admin vulnerable to Insecure PermissionsCVE-2023-34062Highio.projectreactor.netty:reactor-netty-http: In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attackCVE-2023-5072Highorg.json:json: Java: DoS Vulnerability in JSON-JAVAGHSA-72FP-W44G-625QLowsoftware.amazon.cryptography:aws-database-encryption-sdk-dynamodb: Signing DynamoDB Sets when using the AWS Database Encryption SDK.CVE-2023-46732Criticalorg.xwiki.platform:xwiki-platform-flamingo-skin-resources: XWiki Platform vulnerable to reflected cross-site scripting through revision parameter in content menuCVE-2023-46731Criticalorg.xwiki.platform:xwiki-platform-administration-ui: XWiki Platform vulnerable to remote code execution through the section parameter in Administration as guestCVE-2023-39913Highorg.apache.uima:uimaj: Apache UIMA Java SDK Deserialization of Untrusted Data, Improper Input Validation vulnerabilityCVE-2023-4061Mediumorg.wildfly.core:wildfly-controller: wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityCVE-2023-46244Criticalorg.xwiki.platform:xwiki-platform-display-api: XWiki Platform privilege escalation from script right to programming right through title displayerCVE-2023-46243Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform vulnerable to privilege escalation and remote code execution via the edit actionCVE-2023-46242Criticalorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform vulnerable to remote code execution via the edit action because it lacks CSRF tokenCVE-2023-4043Mediumorg.eclipse.parsson:project: Eclipse Parsson Denial of Service vulnerabilityCVE-2023-5763Mediumorg.glassfish.main.orb:orb-connector: Eclipse Glassfish remote code execution issueCVE-2023-31579Hightop.tangyh.basic:lamp-core: Dromara Lamp-Cloud Use of Hard-coded Cryptographic KeyCVE-2023-46502Criticalorg.opencrx:opencrx-client: OpenCRX allows a remote attacker to execute arbitrary code via a crafted request

Stop the waste.
Protect your environment with Kodem.