Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-41932Mediumorg.jenkins-ci.plugins:jobConfigHistory: Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History PluginCVE-2023-40743Criticalorg.apache.axis:axis: Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getServiceCVE-2023-41046Mediumorg.xwiki.platform:xwiki-platform-oldcore: Velocity execution without script right through VelocityCode and VelocityWiki propertyCVE-2023-40771Highio.dataease:dataease-plugin-common: DataEase vulnerable to SQL injectionCVE-2023-39685Highorg.hjson:hjson: hson-java vulnerable to denial of serviceCVE-2023-41034Mediumorg.eclipse.leshan:leshan-core: DDFFileParser is vulnerable to XXE AttacksCVE-2023-40787Highorg.springblade:blade-core-tool: SpringBlade vulnerable to SQL injectionCVE-2023-40826Highorg.pf4j:pf4j: pf4j vulnerable to remote code execution via the zippluginPath parameterCVE-2023-40828Highorg.pf4j:pf4j: pf4j vulnerable to remote code execution via expandIfZip method in the extract functionCVE-2023-40827Highorg.pf4j:pf4j: pf4j vulnerable to remote code execution via loadpluginPath parameterCVE-2023-41080Mediumorg.apache.tomcat:tomcat: Apache Tomcat Open Redirect vulnerabilityCVE-2023-24620Mediumcom.esotericsoftware.yamlbeans:yamlbeans: Esoteric YamlBeans XML Entity Expansion vulnerabilityCVE-2023-24621Highcom.esotericsoftware.yamlbeans:yamlbeans: Esoteric YamlBeans Unsafe Deserialization vulnerabilityCVE-2023-34040Highorg.springframework.kafka:spring-kafka: Spring-Kafka has Java Deserialization vulnerability When Improperly ConfiguredCVE-2023-40573Criticalorg.xwiki.platform:xwiki-platform-scheduler-api: XWiki Platform's Groovy jobs check the wrong author, allowing remote code executionCVE-2023-40572Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create actionCVE-2022-44729Highorg.apache.xmlgraphics:batik-bridge: Apache XML Graphics Batik Server-Side Request Forgery vulnerabilityCVE-2022-44730Mediumorg.apache.xmlgraphics:batik-script: Apache Batik information disclosure vulnerabilityCVE-2023-4303Mediumorg.jenkins-ci.plugins:fortify: Jenkins Fortify Plugin HTML injection vulnerabilityCVE-2023-4301Mediumorg.jenkins-ci.plugins:fortify: Jenkins Fortify Plugin cross-site request forgery vulnerabilityCVE-2023-4302Mediumorg.jenkins-ci.plugins:fortify: Jenkins Fortify Plugin missing permission checkCVE-2023-40177Criticalorg.xwiki.platform:xwiki-platform-appwithinminutes-ui: XWiki Platform privilege escalation (PR) from account through AWM content fieldsCVE-2023-40176Mediumorg.xwiki.platform:xwiki-platform-web-templates: XWiki Platform Stored Cross-site Scripting in the user profile via the timezone displayerCVE-2023-39106Highcom.alibaba.nacos:nacos-spring-context: Nacos Spring vulnerable to Unsafe DeserializationCVE-2022-46751Highorg.apache.ivy:ivy: Apache Ivy External Entity Reference vulnerability

Stop the waste.
Protect your environment with Kodem.