Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-33201Mediumorg.bouncycastle:bcprov-jdk18on: Bouncy Castle For Java LDAP injection vulnerabilityCVE-2023-2974Mediumio.quarkus:quarkus-core: quarkus-core vulnerable to client driven TLS cipher downgradingCVE-2023-36812Criticalnet.opentsdb:opentsdb: Remote Code Execution for 2.4.1 and earlierCVE-2023-36468Criticalorg.xwiki.platform:xwiki-platform-oldcore: Upgrading doesn't prevent exploiting vulnerable XWiki documentsCVE-2023-36469Criticalorg.xwiki.platform:xwiki-platform-notifications-ui: XWiki Platform vulnerable to Code injection through NotificationRSSServiceCVE-2023-36470Criticalorg.xwiki.platform:xwiki-platform-icon-default: XWiki Platform vulnerable to Code Injection in icon themesCVE-2023-36471Criticalorg.xwiki.commons:xwiki-commons-xml: org.xwiki.commons:xwiki-commons-xml's HTML sanitizer allows form elements in restrictedCVE-2023-36477Criticalorg.xwiki.platform:xwiki-platform-ckeditor-ui: XWiki Platform vulnerable to persistent Cross-site Scripting through CKEditor Configuration pagesCVE-2023-2422Highorg.keycloak:keycloak-services: Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clientsCVE-2022-4361Criticalorg.keycloak:keycloak-services: Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDCCVE-2023-1664Mediumorg.keycloak:keycloak-core: Keycloak Untrusted Certificate Validation vulnerabilityCVE-2023-2585Loworg.keycloak:keycloak-services: Client Spoofing within the Keycloak Device Authorisation GrantCVE-2023-3432Highnet.sourceforge.plantuml:plantuml-mit: PlantUML Server-Side Request Forgery vulnerabilityCVE-2023-3431Mediumnet.sourceforge.plantuml:plantuml-mit: PlantUML Improper Access Control vulnerabilityCVE-2021-31635Criticalcom.jfinal:jfinal: jFinal Server-Side Template Injection vulnerabilityCVE-2023-31469Highorg.apache.streampipes:streampipes-parent: Apache StreamPipes Improper Privilege Management vulnerabilityCVE-2023-25499Mediumcom.vaadin:vaadin: Vaadin vulnerable to possible information disclosure in non visible components.CVE-2023-25500Lowcom.vaadin:flow-server: Vaadin vulnerable to possible information disclosure of class and method names in RPC responseCVE-2023-35925Mediumcom.fastasyncworldedit:FastAsyncWorldEdit-Core: FastAsyncWorldEdit vulnerable to Uncontrolled Resource ConsumptionCVE-2023-35161Criticalorg.xwiki.platform:xwiki-platform-appwithinminutes-ui: XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication pageCVE-2023-35160Criticalorg.xwiki.platform:xwiki-platform-web-templates: XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit templateCVE-2023-35159Criticalorg.xwiki.platform:xwiki-platform-web-templates: XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace templateCVE-2023-35158Criticalorg.xwiki.platform:xwiki-platform-flamingo-skin-resources: XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore templateCVE-2023-35157Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform vulnerable to reflected cross-site scripting via delattachment actionCVE-2023-35156Criticalorg.xwiki.platform:xwiki-platform-flamingo-skin-resources: XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template

Stop the waste.
Protect your environment with Kodem.