Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-24839Highorg.nokogiri:nekohtml: org.nokogiri:nekohtml vulnerable to Uncontrolled Resource ConsumptionCVE-2023-33725Mediumorg.broadleafcommerce:broadleaf: Broadleaf vulnerable to Cross-site ScriptingCVE-2023-34981Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat vulnerable to information leakCVE-2023-34340Criticalorg.apache.accumulo:accumulo-shell: Apache Accumulo Improper Authentication vulnerabilityCVE-2023-35166Highorg.xwiki.platform:xwiki-platform-help-ui: XWiki Platform vulnerable to privilege escalation (PR) from account through TipsPanelCVE-2023-35162Criticalorg.xwiki.platform:xwiki-platform-flamingo-skin-resources: XWiki Platform vulnerable to cross-site scripting via xcontinue parameter in previewactions templateCVE-2023-35155Highorg.xwiki.platform:xwiki-platform-sharepage-api: XWiki Platform vulnerable to cross-site scripting in target parameter via share page by emailCVE-2023-35153Criticalorg.xwiki.platform:xwiki-platform-appwithinminutes-ui: XWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parametersCVE-2023-35152Criticalorg.xwiki.platform:xwiki-platform-like-ui: XWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResultsCVE-2023-35151Highorg.xwiki.platform:xwiki-platform-rest-server: XWiki Platform may show email addresses in clear in REST resultsCVE-2023-35150Criticalorg.xwiki.platform:xwiki-platform-invitation-ui: XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation applicationCVE-2023-34467Highorg.xwiki.platform:xwiki-platform-livetable-ui: XWiki Platform may retrieve email addresses of all users CVE-2023-34466Mediumorg.xwiki.platform:xwiki-platform-tag-api: XWiki Platform's tags on non-viewable pages can be revealed to usersCVE-2023-34465Criticalorg.xwiki.platform:xwiki-platform-mail-send-default: XWiki Platform's Mail.MailConfig can be edited by any user with edit rightsCVE-2023-34464Criticalorg.xwiki.platform:xwiki-platform-web: XWiki vulnerable to stored cross-site scripting via any wiki document and the displaycontent/rendercontent templateCVE-2023-34462Mediumio.netty:netty-handler: netty-handler SniHandler 16MB allocationCVE-2020-21485Mediumorg.alluxio:alluxio-parent: Alluxio Cross Site Scripting vulnerabilityCVE-2023-3315Mediumorg.jenkins-ci.plugins:teamconcert: Jenkins Team Concert Plugin does not perform permission checks in methods implementing form validationCVE-2023-34603Mediumorg.jeecgframework.boot:jeecg-boot-parent: JeecgBoot vulnerable to SQL injection in queryFilterTableDictInfoCVE-2023-34602Mediumorg.jeecgframework.boot:jeecg-boot-parent: JeecgBoot vulnerable to SQL injection in queryTableDictItemsByCodeCVE-2023-35839Criticalorg.noear:solon: Solon vulnerable to deserialization of untrusted dataCVE-2023-3308Mediumcom.whaleal.icefrog:icefrog-all: Whaleal IceFrog is vulnerable to deserialization CVE-2023-34660Mediumorg.jeecgframework.boot:jeecg-boot-parent: jeecg-boot unrestricted file upload vulnerabilityCVE-2023-34659Criticalorg.jeecgframework.boot:jeecg-boot-parent: jeecg-boot SQL injection vulnerabilityCVE-2023-34455Highorg.xerial.snappy:snappy-java: snappy-java's unchecked chunk length leads to DoS

Stop the waste.
Protect your environment with Kodem.