Maven Package Vulnerabilities

All 3,122 Java / JVM artifacts with known CVEs, ranked by live CVE volume — 8,138 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 501.io.netty:netty-handler-ssl-ocsp3 CVEs
  2. 502.io.netty:netty-resolver-dns3 CVEs
  3. 503.io.opentelemetry.javaagent:opentelemetry-javaagent3 CVEs
  4. 504.io.ratpack:ratpack-session3 CVEs
  5. 505.net.bull.javamelody:javamelody-core3 CVEs
  6. 506.net.lingala.zip4j:zip4j3 CVEs
  7. 507.net.praqma:rqm-plugin3 CVEs
  8. 508.net.sourceforge.pmd:pmd-core3 CVEs
  9. 509.org.apache.activemq:activemq-core3 CVEs
  10. 510.org.apache.activemq:activemq-web-console3 CVEs
  11. 511.org.apache.activemq:artemis-server3 CVEs
  12. 512.org.apache.archiva:archiva-common3 CVEs
  13. 513.org.apache.axis2:axis23 CVEs
  14. 514.org.apache.calcite:calcite-core3 CVEs
  15. 515.org.apache.cxf:cxf-rt-transports-http3 CVEs
  16. 516.org.apache.cxf.fediz:fediz-spring3 CVEs
  17. 517.org.apache.druid:druid-core3 CVEs
  18. 518.org.apache.flume.flume-ng-sources:flume-jms-source3 CVEs
  19. 519.org.apache.geronimo.plugins:console3 CVEs
  20. 520.org.apache.hive:hive-jdbc3 CVEs
  21. 521.org.apache.inlong:inlong-manager3 CVEs
  22. 522.org.apache.inlong:manager-common3 CVEs
  23. 523.org.apache.ivy:ivy3 CVEs
  24. 524.org.apache.jackrabbit:jackrabbit-core3 CVEs
  25. 525.org.apache.jmeter:ApacheJMeter3 CVEs
  26. 526.org.apache.kylin:kylin-common-server3 CVEs
  27. 527.org.apache.livy:livy-server3 CVEs
  28. 528.org.apache.myfaces.core:myfaces-core-module3 CVEs
  29. 529.org.apache.neethi:neethi3 CVEs
  30. 530.org.apache.nifi:nifi-jms-processors3 CVEs
  31. 531.org.apache.olingo:odata-client-core3 CVEs
  32. 532.org.apache.oozie:oozie-core3 CVEs
  33. 533.org.apache.portals.jetspeed-2:jetspeed3 CVEs
  34. 534.org.apache.portals.pluto:pluto-portal3 CVEs
  35. 535.org.apache.pulsar:pulsar-proxy3 CVEs
  36. 536.org.apache.qpid:apache-qpid-broker-j3 CVEs
  37. 537.org.apache.shenyu:shenyu-admin3 CVEs
  38. 538.org.apache.shiro:shiro-spring3 CVEs
  39. 539.org.apache.sling:org.apache.sling.api3 CVEs
  40. 540.org.apache.sling:org.apache.sling.cms3 CVEs
  41. 541.org.apache.sling:org.apache.sling.xss3 CVEs
  42. 542.org.apache.sling:org.apache.sling.xss.compat3 CVEs
  43. 543.org.apache.spark:spark-core_2.123 CVEs
  44. 544.org.apache.spark:spark-core_2.133 CVEs
  45. 545.org.apache.sshd:sshd-common3 CVEs
  46. 546.org.apache.sshd:sshd-core3 CVEs
  47. 547.org.apache.struts:struts2-parent3 CVEs
  48. 548.org.apache.syncope:syncope3 CVEs
  49. 549.org.apache.tomcat:tomcat-jasper3 CVEs
  50. 550.org.apache.tomcat:tomcat-tribes3 CVEs

Which Maven packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →