Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-39155Loworg.jenkins-ci.plugins:chef-identity: Secret displayed without masking by Chef Identity Plugin CVE-2023-39152Mediumorg.jenkins-ci.plugins:gradle: Incorrect control flow in Jenkins Gradle Plugin breaks credentials masking in the build logCVE-2023-39156Mediumorg.jenkins-ci.plugins:bazaar: CSRF vulnerability in Bazaar Plugin CVE-2023-38647Criticalorg.apache.helix:helix-core: Deserialization vulnerability in Helix workflow and RESTCVE-2023-38435Mediumorg.apache.felix:org.apache.felix.healthcheck.webconsoleplugin: Cross-site Scripting in healthcheck webconsole pluginCVE-2023-38493Highcom.linecorp.armeria:armeria: Paths contain matrix variables bypass decoratorsCVE-2023-37460Highorg.codehaus.plexus:plexus-archiver: Arbitrary File Creation in AbstractUnArchiverCVE-2023-37895Criticalorg.apache.jackrabbit:jackrabbit-webapp: Remote code execution in Apache JackrabbitCVE-2024-23685Mediumorg.folio:mod-remote-storage: Hard-coded System User Credentials in Folio Data Export Spring module CVE-2024-23687Criticalorg.folio:mod-data-export-spring: Hard-coded System User Credentials in Folio Data Export Spring module CVE-2023-35088Criticalorg.apache.inlong:manager-service: SQL injection in audit endpointCVE-2023-34434Highorg.apache.inlong:manager-pojo: JDBC URL bypassing by allowLoadLocalInfileInPath paramCVE-2023-34189Mediumorg.apache.inlong:inlong-manager: Apache InLong: General user can delete and update processCVE-2023-34478Criticalorg.apache.shiro:shiro-web: Path Traversal in Apache ShiroCVE-2023-3815Lowcom.ruoyi:ruoyi: RuoYi vulnerable to Cross-site ScriptingCVE-2023-37602Mediumorg.opencms:opencms-core: Alkacon OpenCMS arbitrary file upload vulnerabilityCVE-2023-37471Criticalorg.openidentityplatform.openam:openam-federation-library: OpenAM vulnerable to user impersonation using SAMLv1.x SSO processCVE-2023-33265Highcom.hazelcast:hazelcast: Hazelcast Executor Services don't check client permissions properlyCVE-2023-32263Loworg.jenkins-ci.plugins:dimensionsscm: Potential leak of credentials in Micro Focus Dimensions CM Jenkins PluginCVE-2023-32262Mediumorg.jenkins-ci.plugins:dimensionsscm: Exposure of system-scoped credentials in Jenkins Dimensions PluginCVE-2023-32261Mediumorg.jenkins-ci.plugins:dimensionsscm: Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDsCVE-2023-34034Criticalorg.springframework.security:spring-security-config: Access Control Bypass in Spring SecurityCVE-2023-28754Highorg.apache.shardingsphere:shardingsphere: Apache ShardingSphere-Agent Deserialization of Untrusted Data vulnerabilityCVE-2023-0105Mediumorg.keycloak:keycloak-core: Keycloak: Impersonation and lockout possible through incorrect handling of email trustCVE-2023-37476Mediumorg.openrefine:main: OpenRefine vulnerable to zip slip in project import

Stop the waste.
Protect your environment with Kodem.