Maven Package Vulnerabilities

All 3,123 Java / JVM artifacts with known CVEs, ranked by live CVE volume — 8,143 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 801.io.micrometer:micrometer-core2 CVEs
  2. 802.io.micronaut:micronaut-http-server2 CVEs
  3. 803.io.micronaut:micronaut-http-server-netty2 CVEs
  4. 804.io.modelcontextprotocol.sdk:mcp-core2 CVEs
  5. 805.io.netty:netty-all2 CVEs
  6. 806.io.netty:netty-codec-classes-quic2 CVEs
  7. 807.io.netty:netty-codec-dns2 CVEs
  8. 808.io.netty:netty-codec-stomp2 CVEs
  9. 809.io.netty:netty-codec-xml2 CVEs
  10. 810.io.netty:netty-common2 CVEs
  11. 811.io.netty:netty-transport-native-epoll2 CVEs
  12. 812.io.netty:netty-transport-sctp2 CVEs
  13. 813.io.pebbletemplates:pebble2 CVEs
  14. 814.io.projectreactor.netty:reactor-netty2 CVEs
  15. 815.io.qameta.allure:allure-generator2 CVEs
  16. 816.io.quarkiverse.openapi.generator:quarkus-openapi-generator2 CVEs
  17. 817.io.quarkus:quarkus-core2 CVEs
  18. 818.io.quarkus:quarkus-rest2 CVEs
  19. 819.io.quarkus.resteasy.reactive:resteasy-reactive2 CVEs
  20. 820.io.spinnaker.clouddriver:clouddriver-artifacts2 CVEs
  21. 821.io.spinnaker.orca:orca-core2 CVEs
  22. 822.io.spray:spray-json_2.102 CVEs
  23. 823.io.spray:spray-json_2.112 CVEs
  24. 824.io.spray:spray-json_2.122 CVEs
  25. 825.io.swagger:swagger-parser2 CVEs
  26. 826.javagh.jenkins:mashup-portlets-plugin2 CVEs
  27. 827.jenkins:repository2 CVEs
  28. 828.lsfusion.platform:web-client2 CVEs
  29. 829.net.jpountz.lz4:lz42 CVEs
  30. 830.net.mingsoft:ms-basic2 CVEs
  31. 831.net.praqma:matrix-reloaded2 CVEs
  32. 832.net.sf.jasperreports:jasperreports2 CVEs
  33. 833.net.sf.robocode:robocode.core2 CVEs
  34. 834.net.sourceforge.htmlunit:htmlunit2 CVEs
  35. 835.net.sourceforge.htmlunit:neko-htmlunit2 CVEs
  36. 836.net.sourceforge.plantuml:plantuml2 CVEs
  37. 837.net.sourceforge.plantuml:plantuml-mit2 CVEs
  38. 838.nl.nl-portal:documenten-api2 CVEs
  39. 839.ome:pom-bio-formats2 CVEs
  40. 840.org.6wind.jenkins:lockable-resources2 CVEs
  41. 841.org.alluxio:alluxio-parent2 CVEs
  42. 842.org.apache.activemq:activemq-jaas2 CVEs
  43. 843.org.apache.activemq:activemq-mqtt2 CVEs
  44. 844.org.apache.activemq:activemq-openwire-legacy2 CVEs
  45. 845.org.apache.activemq:activemq-web2 CVEs
  46. 846.org.apache.activemq:apache-artemis2 CVEs
  47. 847.org.apache.activemq:artemis-core-client2 CVEs
  48. 848.org.apache.activemq:artemis-openwire-protocol2 CVEs
  49. 849.org.apache.avro:avro2 CVEs
  50. 850.org.apache.axis2.wso2:axis22 CVEs

Which Maven packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →