Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-4245Mediumorg.codehaus.plexus:plexus-utils: codehaus-plexus vulnerable to XML injectionCVE-2022-4244Highorg.codehaus.plexus:plexus-utils: plexus-codehaus vulnerable to directory traversalCVE-2023-43642Highorg.xerial.snappy:snappy-java: snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impactCVE-2023-40989Criticalorg.jeecgframework.boot:jeecg-boot-common: SQL injection in jeecgbootCVE-2023-43500Mediumcom.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer: Jenkins Build Failure Analyzer Plugin Cross-Site Request Forgery vulnerabilityCVE-2023-43496Highorg.jenkins-ci.main:jenkins-core: Jenkins temporary plugin file created with insecure permissions CVE-2023-43497Loworg.jenkins-ci.main:jenkins-core: Jenkins temporary uploaded file created with insecure permissionsCVE-2023-43495Highorg.jenkins-ci.main:jenkins-core: Jenkins Cross-site Scripting vulnerabilityCVE-2023-43501Mediumcom.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer: Jenkins Build Failure Analyzer Plugin missing permission checkCVE-2023-43502Mediumcom.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer: Jenkins Build Failure Analyzer Plugin Cross-Site Request Forgery vulnerabilityCVE-2023-43499Highcom.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer: Jenkins Build Failure Analyzer Plugin Cross-site Scripting vulnerabilityCVE-2023-43494Mediumorg.jenkins-ci.main:jenkins-core: Jenkins does not exclude sensitive build variables from searchCVE-2023-43498Loworg.jenkins-ci.main:jenkins-core: Jenkins temporary uploaded file created with insecure permissionsCVE-2023-4853Highio.quarkus:quarkus-vertx-http: Quarkus HTTP vulnerable to incorrect evaluation of permissionsCVE-2023-34047Loworg.springframework.graphql:spring-graphql: Spring for GraphQL may be exposed to GraphQL context with values from a different sessionCVE-2022-24816Criticalit.geosolutions.jaiext.jiffle:jt-jiffle: Improper Control of Generation of Code ('Code Injection') in jai-extCVE-2023-4759Highorg.eclipse.jgit:org.eclipse.jgit: Arbitrary File Overwrite in Eclipse JGit CVE-2023-41900Loworg.eclipse.jetty:jetty-openid: Jetty's OpenId Revoked authentication allows one requestCVE-2023-40167Mediumorg.eclipse.jetty:jetty-http: Jetty accepts "+" prefixed value in Content-LengthCVE-2023-36479Loworg.eclipse.jetty:jetty-servlets: Jetty vulnerable to errant command quoting in CGI ServletCVE-2023-1108Highio.undertow:undertow-core: Undertow denial of service vulnerabilityCVE-2023-42503Mediumorg.apache.commons:commons-compress: Apache Commons Compress denial of service vulnerabilityCVE-2023-4918Highorg.keycloak:keycloak-core: Keycloak vulnerable to Plaintext Storage of User PasswordCVE-2023-41887Criticalorg.openrefine:database: OpenRefine Remote Code execution in project import with mysql jdbc url attackCVE-2023-41886Highorg.openrefine:database: OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack

Stop the waste.
Protect your environment with Kodem.