Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-31065Criticalorg.apache.inlong:manager-pojo: Apache InLong Insufficient Session Expiration vulnerabilityCVE-2023-31064Highorg.apache.inlong:manager-workflow: Apache InLong has Files or Directories Accessible to External PartiesCVE-2023-31098Criticalorg.apache.inlong:manager-pojo: Apache InLong has Weak Password Requirements in Apache InLongCVE-2023-31066Criticalorg.apache.inlong:manager-service: Apache InLong has Files or Directories Accessible to External Parties in Apache InLongCVE-2023-28709Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat - Fix for CVE-2023-24998 was incompleteCVE-2023-31062Criticalorg.apache.inlong:manager-pojo: Apache InLong Improper Privilege Management vulnerabilityCVE-2023-31206Highorg.apache.inlong:manager-pojo: Apache InLong Exposure of Resource to Wrong Sphere vulnerabilityCVE-2023-31058Highorg.apache.inlong:manager-pojo: Apache InLong Deserialization of Untrusted Data VulnerabilityCVE-2023-28936Mediumorg.apache.openmeetings:openmeetings-db: Apache OpenMeetings insufficient authorization vulnerabilityCVE-2022-45048Highorg.apache.ranger:ranger: Apache Ranger code execution vulnerability in policy expressionsCVE-2023-41044Loworg.graylog2:graylog2-server: Graylog server has partial path traversal vulnerability in Support Bundle featureCVE-2023-41045Loworg.graylog2:graylog2-server: Graylog vulnerable to insecure source port usage for DNS queriesCVE-2023-41041Loworg.graylog2:graylog2-server: Graylog user session is still usable after logoutCVE-2022-45802Criticalorg.apache.streampark:streampark-common_2.12: Apache StreamPark Path Traversal vulnerabilityCVE-2022-46365Criticalorg.apache.streampark:streampark: Apache StreamPark Improper Input Validation vulnerabilityCVE-2023-30465Mediumorg.apache.inlong:manager-pojo: Apache InLong SQL Injection vulnerabilityCVE-2023-27987Criticalorg.apache.linkis:linkis: Apache Linkis Authentication Bypass vulnerabilityCVE-2023-26119Criticalnet.sourceforge.htmlunit:htmlunit: HtmlUnit Code Injection vulnerabilityCVE-2023-27602Criticalorg.apache.linkis:linkis: Apache Linkis Unrestricted File Upload vulnerabilityCVE-2023-27603Criticalorg.apache.linkis:linkis: Apache Linkis Zip Slip issueCVE-2023-28685Highorg.jenkins-ci.plugins:absint-a3: Jenkins AbsInt a³ Plugin XML External Entity Reference vulnerabilityCVE-2021-28655Mediumorg.apache.zeppelin:zeppelin: Apache Zeppelin Improper Input Validation vulnerabilityCVE-2022-24697Criticalorg.apache.kylin:kylin-core-common: Apache Kylin vulnerable to remote code executionCVE-2023-32731Highio.grpc:grpc-protobuf: Connection confusion in gRPCCVE-2023-34150Mediumorg.apache.any23:apache-any23: Apache Any23 vulnerable to excessive memory usage

Stop the waste.
Protect your environment with Kodem.