Maven Package Vulnerabilities

All 3,123 Java / JVM artifacts with known CVEs, ranked by live CVE volume — 8,142 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 701.com.esotericsoftware.yamlbeans:yamlbeans2 CVEs
  2. 702.com.fasterxml.jackson.dataformat:jackson-dataformat-xml2 CVEs
  3. 703.com.gitblit:gitblit2 CVEs
  4. 704.com.github.liuyueyi.media:batik-codec-fix2 CVEs
  5. 705.com.github.psi-probe:psi-probe-core2 CVEs
  6. 706.com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent2 CVEs
  7. 707.com.google.oauth-client:google-oauth-client2 CVEs
  8. 708.com.google.protobuf:protobuf-kotlin-lite2 CVEs
  9. 709.com.inflectra.spiratest.plugins:inflectra-spira-integration2 CVEs
  10. 710.com.itextpdf:itextpdf2 CVEs
  11. 711.com.liferay:com.liferay.adaptive.media.web2 CVEs
  12. 712.com.liferay:com.liferay.asset.taglib2 CVEs
  13. 713.com.liferay:com.liferay.document.library.web2 CVEs
  14. 714.com.liferay:com.liferay.frontend.js.web2 CVEs
  15. 715.com.liferay:com.liferay.frontend.taglib2 CVEs
  16. 716.com.liferay:com.liferay.journal.web2 CVEs
  17. 717.com.liferay:com.liferay.layout.impl2 CVEs
  18. 718.com.liferay:com.liferay.layout.taglib2 CVEs
  19. 719.com.liferay:com.liferay.object.web2 CVEs
  20. 720.com.liferay:com.liferay.organizations.item.selector.web2 CVEs
  21. 721.com.liferay:com.liferay.portal.security.ldap.impl2 CVEs
  22. 722.com.liferay:com.liferay.portal.workflow.kaleo.designer.web2 CVEs
  23. 723.com.liferay:com.liferay.portal.workflow.kaleo.forms.web2 CVEs
  24. 724.com.liferay:com.liferay.server.admin.web2 CVEs
  25. 725.com.liferay:com.liferay.site.admin.web2 CVEs
  26. 726.com.liferay:com.liferay.translation.web2 CVEs
  27. 727.com.liferay.portal:com.liferay.util.java2 CVEs
  28. 728.com.liferay.portal:portal-impl2 CVEs
  29. 729.com.liferay.portal:portal-service2 CVEs
  30. 730.com.mchange:mchange-commons-java2 CVEs
  31. 731.com.meowlomo.jenkins:scm-httpclient2 CVEs
  32. 732.commons-io:commons-io2 CVEs
  33. 733.com.nepxion:discovery2 CVEs
  34. 734.com.ning:async-http-client2 CVEs
  35. 735.com.okta.sdk:okta-sdk-root2 CVEs
  36. 736.com.ongres.scram:scram-common2 CVEs
  37. 737.com.openmake:deployhub2 CVEs
  38. 738.com.openshift.jenkins:openshift-pipeline2 CVEs
  39. 739.com.opensymphony:xwork2 CVEs
  40. 740.com.orientechnologies:orientdb-studio2 CVEs
  41. 741.com.paul8620.jenkins.plugins:pipeline-aggregator-view2 CVEs
  42. 742.com.powsybl:powsybl-commons2 CVEs
  43. 743.com.puppycrawl.tools:checkstyle2 CVEs
  44. 744.com.qualys.plugins:qualys-pc2 CVEs
  45. 745.com.qualys.plugins:qualys-was2 CVEs
  46. 746.com.redgate.plugins.redgatesqlci:redgate-sql-ci2 CVEs
  47. 747.com.sap.cloud.security:java-security2 CVEs
  48. 748.com.sap.cloud.security:spring-security2 CVEs
  49. 749.com.sap.cloud.security.xsuaa:spring-xsuaa2 CVEs
  50. 750.com.softwaremill.akka-http-session:core_2.122 CVEs

Which Maven packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →