Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-7C2Q-5QMR-V76QHighorg.owasp.esapi:esapi: DoS vulnerabilities persist in ESAPI file uploads despite remediation of CVE-2023-24998CVE-2023-46604Criticalorg.apache.activemq:activemq-client: Apache ActiveMQ is vulnerable to Remote Code ExecutionCVE-2023-31417Mediumorg.elasticsearch:elasticsearch: Elasticsearch allows insertion of sensitive information into log files when using deprecated URIsCVE-2023-31418Highorg.elasticsearch:elasticsearch: Elasticsearch vulnerable to Uncontrolled Resource ConsumptionCVE-2023-31419Mediumorg.elasticsearch:elasticsearch: Elasticsearch vulnerable to stack overflow in the search APICVE-2023-45137Criticalorg.xwiki.platform:xwiki-platform-web-templates: XWiki Platform vulnerable to XSS with edit right in the create document form for existing pagesCVE-2023-45136Criticalorg.xwiki.platform:xwiki-platform-web-templates: XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabledCVE-2023-45135Criticalorg.xwiki.platform:xwiki-platform-web-templates: XWiki users can be tricked to execute scripts as the create page action doesn't display the page's titleCVE-2023-45134Criticalorg.xwiki.platform:xwiki-platform-web-templates: XWiki Platform XSS vulnerability from account in the create page form via template providerCVE-2023-37913Criticalorg.xwiki.platform:xwiki-platform-office-importer: org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converterCVE-2023-37912Highorg.xwiki.rendering:xwiki-rendering-macro-footnotes: XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macroCVE-2023-37911Mediumorg.xwiki.platform:xwiki-platform-oldcore: org.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documentsCVE-2023-37910Highorg.xwiki.platform:xwiki-platform-attachment-api: org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment MoveCVE-2023-37909Highorg.xwiki.platform:xwiki-platform-menu: Privilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheetCVE-2023-37908Criticalorg.xwiki.rendering:xwiki-rendering-xml: org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerabilityCVE-2023-46652Mediumorg.jenkins-ci.plugins:lambdatest-automation: Jenkins lambdatest-automation Plugin missing permission checkCVE-2023-46655Mediumorg.jenkins-ci.plugins:electricflow: Jenkins CloudBees CD Plugin vulnerable to arbitrary file readCVE-2023-46651Mediumio.jenkins.plugins:warnings-ng: Jenkins Warnings Plugin exposures system-scoped credentialsCVE-2023-46656Lowigalg.jenkins.plugins:multibranch-scan-webhook-trigger: Jenkins Multibranch Scan Webhook Trigger Plugin uses non-constant time webhook token comparisonCVE-2023-46654Highorg.jenkins-ci.plugins:electricflow: Jenkins CloudBees CD Plugin vulnerable to arbitrary file deletionCVE-2023-46660Loworg.jenkins-ci.plugins:zanata: Non-constant time webhook token hash comparison in Jenkins Zanata PluginCVE-2023-46657Loworg.jenkins-ci.plugins:gogs-webhook: Jenkins Gogs Plugin uses non-constant time webhook token comparisonCVE-2023-46658Lowio.jenkins.plugins:teams-webhook-trigger: Jenkins MSTeams Webhook Trigger Plugin uses non-constant time webhook token comparison CVE-2023-46659Highorg.jenkins-ci.plugins:trac: Jenkins Edgewall Trac Plugin vulnerable to Stored XSSCVE-2023-46653Loworg.jenkins-ci.plugins:lambdatest-automation: Jenkins lambdatest-automation Plugin may expose Credentials access token

Stop the waste.
Protect your environment with Kodem.