Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-46650Highcom.coravy.hudson.plugins.github:github: Stored XSS vulnerability in Jenkins GitHub PluginCVE-2023-43961Highcn.dev33:sa-token-core: SaToken authentication bypass vulnerabilityCVE-2023-44794Criticalcn.dev33:sa-token-core: SaToken privilege escalation vulnerabilityCVE-2023-31582Highorg.bitbucket.b_c:jose4j: jose4j uses weak cryptographic algorithmCVE-2023-31580Mediumcom.networknt:light-oauth2: light-oauth2 missing public key verificationCVE-2023-31581Criticalcom.usthe.sureness:sureness-core: Sureness uses hardcoded keyCVE-2023-43795Highorg.geoserver.extension:gs-wps-core: WPS Server Side Request Forgery vulnerabilityCVE-2023-41339Mediumorg.geoserver:gs-wms: Unsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRFCVE-2023-46122Loworg.scala-sbt:sbt: sbt vulnerable to arbitrary file write via archive extraction (Zip Slip)CVE-2023-46120Mediumcom.rabbitmq:amqp-client: RabbitMQ Java client's Lack of Message Size Limitation leads to Remote DoS AttackCVE-2023-44483Mediumorg.apache.santuario:xmlsec: Apache Santuario - XML Security for Java are vulnerable to private key disclosureCVE-2023-45280Mediumorg.yamcs:yamcs: Yamcs Cross-site Scripting vulnerabilityCVE-2023-45279Mediumorg.yamcs:yamcs: Yamcs Cross-site Scripting vulnerabilityCVE-2023-45277Highorg.yamcs:yamcs: Yamcs Path Traversal vulnerabilityCVE-2023-45278Criticalorg.yamcs:yamcs: Yamcs API Directory Traversal vulnerabilityCVE-2023-46227Highorg.apache.inlong:manager-common: Apache InLong Deserialization of Untrusted Data VulnerabilityCVE-2023-25753Mediumorg.apache.shenyu:shenyu-admin: Apache Shenyu Server Side Request Forgery vulnerabilityCVE-2023-22102Highcom.mysql:mysql-connector-j: MySQL Connectors takeover vulnerabilityCVE-2023-42627Criticalcom.liferay.commerce:com.liferay.commerce.address.content.web: Liferay Portal and Liferay DXP Vulnerable to XSS in the Commerce ModuleCVE-2023-45807Mediumorg.opensearch.plugin:opensearch-security: OpenSearch Issue with tenant read-only permissionsGHSA-8WX3-324G-W4QQHighorg.opensearch.plugin:opensearch-security: OpenSearch uncontrolled resource consumptionCVE-2023-45669Mediumcom.webauthn4j:webauthn4j-spring-security-core: WebAuthn4J Spring Security Improper signature counter value handlingCVE-2023-45144Criticalcom.xwiki.identity-oauth:identity-oauth-ui: XWiki Identity Oauth Privilege escalation (PR)/remote code execution from login screen through unescaped URL parameterCVE-2023-44311Criticalcom.liferay:com.liferay.oauth2.provider.rest: Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect ClassCVE-2023-42628Criticalcom.liferay:com.liferay.wiki.web: Liferay Portal and Liferay DXP Vulnerable to XSS in the Wiki Widget

Stop the waste.
Protect your environment with Kodem.