Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-34454Mediumorg.xerial.snappy:snappy-java: snappy-java's Integer Overflow vulnerability in compress leads to DoSCVE-2023-34453Mediumorg.xerial.snappy:snappy-java: snappy-java's Integer Overflow vulnerability in shuffle leads to DoSCVE-2023-3276Highcn.hutool:hutool-core: HuTool XML parsing module has blind XXE vulnerabilityCVE-2023-35029Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout ModuleCVE-2023-35030Highcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to CSRF via the Layout ModuleCVE-2023-3193Mediumcom.liferay.portal:release.portal.bom: Liferay Portal and Liferay DXP Vulnerable to XSS via the Layout ModuleCVE-2023-2976Mediumcom.google.guava:guava: Guava vulnerable to insecure use of temporary directoryCVE-2023-35110Highde.grobmeier.json:jjson: jjson vulnerable to stack exhaustionCVE-2023-34624Highnet.sourceforge.htmlcleaner:htmlcleaner: htmlcleaner vulnerable to stack exhaustionCVE-2023-34616Highcom.progsbase.libraries:JSON: pbjson vulnerable to stack exhaustionCVE-2023-34613Highnet.sf.sojo:sojo: sojo vulnerable to stack exhaustionCVE-2023-34620Highorg.hjson:hjson: hjson stack exhaustion vulnerabilityCVE-2023-34614Highcc.plural:jsonij: jsonij vulnerable to stack exhaustionCVE-2023-34617Highcom.owlike:genson: genson vulnerable to stack exhaustionCVE-2023-34612Highcom.helger.commons:ph-json: ph-json vulnerable to stack exhaustionCVE-2023-34615Highnet.pwall.json:jsonutil: JSONUtil vulnerable to stack exhaustionCVE-2023-34610Highcom.cedarsoftware:json-io: json-io vulnerable to stack exhaustionCVE-2023-35148Mediumorg.jenkins-ci.plugins:ease-plugin: Jenkins Digital.ai App Management Publisher Plugin vulnerable to Cross-Site Request ForgeryCVE-2023-35144Mediumjenkins:repository: Stored XSS vulnerability in Jenkins Maven Repository Server PluginCVE-2023-35145Highorg.jenkins-ci.plugins:sonargraph-integration: Jenkins Sonargraph Integration Plugin vulnerable to Stored Cross-site ScriptingCVE-2023-35146Highorg.jenkins.plugin.templateWorkflows:template-workflows: Jenkins Template Workflows Plugin vulnerable to Stored Cross-site ScriptingCVE-2023-35147Mediumorg.jenkins-ci.plugins:aws-codecommit-trigger: Arbitrary file read vulnerability in Jenkins AWS CodeCommit Trigger PluginCVE-2023-35149Mediumorg.jenkins-ci.plugins:ease-plugin: Jenkins Digital.ai App Management Publisher Plugin missing permission checksCVE-2023-35142Highcom.checkmarx.jenkins:checkmarx: SSL/TLS certificate validation disabled by default in Jenkins Checkmarx PluginCVE-2023-35141Highorg.jenkins-ci.main:jenkins-core: Jenkins CSRF protection bypass vulnerability

Stop the waste.
Protect your environment with Kodem.