Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-37948Mediumorg.jenkins-ci.plugins:oracle-cloud-infrastructure-compute: Jenkins Oracle Cloud Infrastructure Compute Plugin missing SSH host key validationCVE-2023-37957Highio.jenkins.plugins:pipeline-restful-api: Jenkins Pipeline restFul API Plugin vulnerable to Cross Site Request ForgeryCVE-2023-37942Mediumorg.jenkins-ci.plugins:external-monitor-job: Jenkins External Monitor Job Type Plugin XML external entity vulnerabilityCVE-2023-37944Mediumorg.datadog.jenkins.plugins:datadog: Jenkins Datadog Plugin does not perform a permission check in an HTTP endpoint.CVE-2023-37943Mediumorg.jenkins-ci.plugins:active-directory: Jenkins Active Directory Plugin vulnerable to Active Directory credential disclosureCVE-2023-37579Mediumorg.apache.pulsar:pulsar-functions-worker: Apache Pulsar Function Worker Incorrect Authorization vulnerabilityCVE-2023-37582Criticalorg.apache.rocketmq:rocketmq-namesrv: RocketMQ NameServer component Code Injection vulnerabilityCVE-2023-30428Highorg.apache.pulsar:pulsar-broker: Apache Pulsar Broker's Rest Producer vulnerable to Incorrect AuthorizationCVE-2023-30429Criticalorg.apache.pulsar:pulsar: Apache Pulsar Incorrect Authorization vulnerabilityCVE-2023-31007Mediumorg.apache.pulsar:pulsar-broker: Apache Pulsar Broker Improper Authentication vulnerabilityCVE-2022-45855Highorg.apache.ambari:ambari: Apache Ambari Expression Language Injection vulnerabilityCVE-2022-42009Highorg.apache.ambari:ambari: Apache Ambari Expression Language Injection vulnerabilityCVE-2023-32200Highorg.apache.jena:jena: Apache Jena Expression Language Injection vulnerabilityCVE-2023-37277Criticalorg.xwiki.platform:xwiki-platform-rest-server: XWiki Platform vulnerable to cross-site request forgery (CSRF) via the REST APIGHSA-58QW-P7QM-5RVHLoworg.eclipse.jetty:jetty-xml: Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarationsCVE-2023-35887Mediumorg.apache.sshd:sshd-core: Apache MINA SSHD information disclosure vulnerabilityCVE-2023-34442Loworg.apache.camel:camel-jira: Apache Camel information exposure vulnerabilityCVE-2023-33008Mediumorg.apache.johnzon:johnzon-mapper: Apache Johnzon Deserialization of Untrusted Data vulnerabilityCVE-2023-32732Mediumio.grpc:grpc-protobuf: gRPC connection termination issueCVE-2023-1428Highio.grpc:grpc-protobuf: gRPC Reachable Assertion issueCVE-2023-30601Highorg.apache.cassandra:cassandra-all: Apache Cassandra: Privilege escalation when enabling FQL/Audit logsCVE-2023-33246Criticalorg.apache.rocketmq:rocketmq-broker: Apache RocketMQ may have remote code execution vulnerability when using update configuration functionCVE-2023-31454Highorg.apache.inlong:manager-service: Apache InLong vulnerable to Incorrect Permission Assignment for Critical ResourceCVE-2023-31103Highorg.apache.inlong:manager-pojo: Apache InLong Exposure of Resource to Wrong Sphere vulnerabilityCVE-2023-31453Highorg.apache.inlong:manager-service: Apache InLong Incorrect Permission Assignment for Critical Resource Vulnerability

Stop the waste.
Protect your environment with Kodem.