Maven Package Vulnerabilities

All 3,122 Java / JVM artifacts with known CVEs, ranked by live CVE volume — 8,139 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 651.org.springframework.ldap:spring-ldap-core3 CVEs
  2. 652.org.springframework:spring3 CVEs
  3. 653.org.springframework:spring-context3 CVEs
  4. 654.org.springframework:spring-messaging3 CVEs
  5. 655.org.thymeleaf:thymeleaf3 CVEs
  6. 656.org.thymeleaf:thymeleaf-spring63 CVEs
  7. 657.org.verapdf:validation-model3 CVEs
  8. 658.org.verapdf:validation-model-jakarta3 CVEs
  9. 659.org.webjars.npm:xlsx3 CVEs
  10. 660.org.wildfly.core:wildfly-server3 CVEs
  11. 661.org.wso2.am:am-parent3 CVEs
  12. 662.org.wso2.carbon.registry:carbon-registry3 CVEs
  13. 663.org.xwiki.platform:xwiki-platform-icon-ui3 CVEs
  14. 664.org.xwiki.platform:xwiki-platform-invitation-ui3 CVEs
  15. 665.org.xwiki.platform:xwiki-platform-panels-ui3 CVEs
  16. 666.org.xwiki.platform:xwiki-platform-search-solr-api3 CVEs
  17. 667.org.xwiki.platform:xwiki-platform-security-requiredrights-default3 CVEs
  18. 668.ro.pippo:pippo-core3 CVEs
  19. 669.tech.powerjob:powerjob-server-starter3 CVEs
  20. 670.aendter.jenkins.plugins:filesystem-list-parameter-plugin2 CVEs
  21. 671.ai.djl:api2 CVEs
  22. 672.ch.qos.logback:logback-classic2 CVEs
  23. 673.cn.dev33:sa-token-core2 CVEs
  24. 674.cn.hippo4j:hippo4j-all2 CVEs
  25. 675.cn.hippo4j:hippo4j-core2 CVEs
  26. 676.co.fs2:fs2-io_2.122 CVEs
  27. 677.co.fs2:fs2-io_2.132 CVEs
  28. 678.co.fs2:fs2-io_32 CVEs
  29. 679.com.aizuda:snail-job2 CVEs
  30. 680.com.alauda.jenkins.plugins:alauda-devops-pipeline2 CVEs
  31. 681.com.alipay.sofa:hessian2 CVEs
  32. 682.com.amazonaws:aws-encryption-sdk-java2 CVEs
  33. 683.com.amazonaws:codedeploy2 CVEs
  34. 684.com.apica:ApicaLoadtest2 CVEs
  35. 685.com.arcadedb:arcadedb-server2 CVEs
  36. 686.com.barchart.jenkins:maven-release-cascade2 CVEs
  37. 687.com.blazemeter.plugins:BlazeMeterJenkinsPlugin2 CVEs
  38. 688.com.bstek.ureport:ureport2-console2 CVEs
  39. 689.com.charleskorn.kaml:kaml2 CVEs
  40. 690.com.compuware.jenkins:compuware-ispw-operations2 CVEs
  41. 691.com.compuware.jenkins:compuware-scm-downloader2 CVEs
  42. 692.com.compuware.jenkins:compuware-topaz-utilities2 CVEs
  43. 693.com.compuware.jenkins:compuware-xpediter-code-coverage2 CVEs
  44. 694.com.cronutils:cron-utils2 CVEs
  45. 695.com.datadoghq:dd-java-agent2 CVEs
  46. 696.com.drewnoakes:metadata-extractor2 CVEs
  47. 697.com.erudika:para-core2 CVEs
  48. 698.com.erudika:para-server2 CVEs
  49. 699.com.esotericsoftware.yamlbeans:yamlbeans2 CVEs
  50. 700.com.fasterxml.jackson.dataformat:jackson-dataformat-xml2 CVEs

Which Maven packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →