Maven Package Vulnerabilities

All 3,216 Java / JVM artifacts with known CVEs, ranked by live CVE volume — 8,471 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 51.tools.jackson.core:jackson-databind15 CVEs
  2. 52.org.apache.cxf:cxf-core14 CVEs
  3. 53.org.bouncycastle:bc-fips14 CVEs
  4. 54.io.netty:netty-handler13 CVEs
  5. 55.org.apache.hadoop:hadoop-main13 CVEs
  6. 56.org.apache.kylin:kylin13 CVEs
  7. 57.org.apache.tika:tika-core13 CVEs
  8. 58.org.jenkins-ci.plugins:git13 CVEs
  9. 59.org.jenkins-ci.plugins.workflow:workflow-cps13 CVEs
  10. 60.org.springframework:spring-web13 CVEs
  11. 61.org.apache.activemq:activemq-broker12 CVEs
  12. 62.org.apache.cassandra:cassandra-all12 CVEs
  13. 63.org.apache.cxf:cxf12 CVEs
  14. 64.org.apache.hadoop:hadoop-common12 CVEs
  15. 65.org.apache.shiro:shiro-core12 CVEs
  16. 66.org.apache.streampark:streampark12 CVEs
  17. 67.org.bouncycastle:bcprov-jdk18on12 CVEs
  18. 68.org.jeecgframework.boot:jeecg-boot-parent12 CVEs
  19. 69.org.jenkins-ci.plugins:active-directory12 CVEs
  20. 70.org.jenkins-ci.plugins:email-ext12 CVEs
  21. 71.com.xuxueli:xxl-job11 CVEs
  22. 72.io.netty:netty11 CVEs
  23. 73.org.apache.activemq:activemq-all11 CVEs
  24. 74.org.apache.archiva:archiva11 CVEs
  25. 75.org.apache.camel:camel-core11 CVEs
  26. 76.org.apache.commons:commons-compress11 CVEs
  27. 77.org.apache.james:james-server11 CVEs
  28. 78.org.apache.jspwiki:jspwiki-war11 CVEs
  29. 79.org.apache.logging.log4j:log4j-core11 CVEs
  30. 80.org.http4s:http4s-ember-core_2.1211 CVEs
  31. 81.org.http4s:http4s-ember-core_2.1311 CVEs
  32. 82.org.http4s:http4s-ember-core_311 CVEs
  33. 83.org.igniterealtime.openfire:parent11 CVEs
  34. 84.org.mortbay.jetty:jetty11 CVEs
  35. 85.org.xwiki.platform:xwiki-platform-administration-ui11 CVEs
  36. 86.org.xwiki.platform:xwiki-platform-rest-server11 CVEs
  37. 87.struts:struts11 CVEs
  38. 88.ca.uhn.hapi.fhir:org.hl7.fhir.r510 CVEs
  39. 89.ca.uhn.hapi.fhir:org.hl7.fhir.validation10 CVEs
  40. 90.ch.qos.logback:logback-core10 CVEs
  41. 91.com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer10 CVEs
  42. 92.com.vaadin:flow-server10 CVEs
  43. 93.io.netty:netty-codec-http210 CVEs
  44. 94.org.apache.hive:hive-exec10 CVEs
  45. 95.org.apache.inlong:manager-service10 CVEs
  46. 96.org.apache.linkis:linkis10 CVEs
  47. 97.org.apache.spark:spark-core_2.1110 CVEs
  48. 98.org.craftercms:crafter-studio10 CVEs
  49. 99.org.jboss.netty:netty10 CVEs
  50. 100.org.jenkins-ci.plugins.workflow:workflow-cps-global-lib10 CVEs

Which Maven packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Book a Demo →