Maven Package Vulnerabilities

All 3,216 Java / JVM artifacts with known CVEs, ranked by live CVE volume — 8,471 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 101.org.postgresql:postgresql10 CVEs
  2. 102.cn.hutool:hutool-core9 CVEs
  3. 103.com.rabbitmq:amqp-client9 CVEs
  4. 104.com.vaadin:vaadin-bom9 CVEs
  5. 105.io.jenkins:configuration-as-code9 CVEs
  6. 106.io.moquette:moquette-broker9 CVEs
  7. 107.mysql:mysql-connector-java9 CVEs
  8. 108.org.apache.dolphinscheduler:dolphinscheduler-api9 CVEs
  9. 109.org.apache.hive:hive9 CVEs
  10. 110.org.apache.spark:spark-core_2.109 CVEs
  11. 111.org.apache.tapestry:tapestry-core9 CVEs
  12. 112.org.apache.xmlgraphics:batik9 CVEs
  13. 113.org.apache.zookeeper:zookeeper9 CVEs
  14. 114.org.asynchttpclient:async-http-client9 CVEs
  15. 115.org.geoserver:gs-wms9 CVEs
  16. 116.org.jenkins-ci.plugins:config-file-provider9 CVEs
  17. 117.org.jenkins-ci.plugins:electricflow9 CVEs
  18. 118.org.keycloak:keycloak-quarkus-server9 CVEs
  19. 119.org.opencrx:opencrx-core-models9 CVEs
  20. 120.org.opennms:opennms9 CVEs
  21. 121.org.silverpeas.core:silverpeas-core-web9 CVEs
  22. 122.ca.uhn.hapi.fhir:org.hl7.fhir.r4b8 CVEs
  23. 123.ca.uhn.hapi.fhir:org.hl7.fhir.utilities8 CVEs
  24. 124.com.ruoyi:ruoyi8 CVEs
  25. 125.io.jenkins.blueocean:blueocean8 CVEs
  26. 126.org.apache.ambari:ambari8 CVEs
  27. 127.org.apache.druid:druid8 CVEs
  28. 128.org.apache.hive:hive-service8 CVEs
  29. 129.org.apache.mina:mina-core8 CVEs
  30. 130.org.apache.ozone:ozone-main8 CVEs
  31. 131.org.apache.pdfbox:pdfbox8 CVEs
  32. 132.org.apache.santuario:xmlsec8 CVEs
  33. 133.org.apache.wicket:wicket-core8 CVEs
  34. 134.org.apache.zeppelin:zeppelin8 CVEs
  35. 135.org.dspace:dspace-api8 CVEs
  36. 136.org.jeecgframework.boot:jeecg-boot-common8 CVEs
  37. 137.org.jenkins-ci.plugins:credentials-binding8 CVEs
  38. 138.org.jenkins-ci.plugins:ec28 CVEs
  39. 139.org.jenkins-ci.plugins:jobConfigHistory8 CVEs
  40. 140.org.jenkins-ci.plugins:oic-auth8 CVEs
  41. 141.org.jenkins-ci.plugins:subversion8 CVEs
  42. 142.org.springframework.cloud:spring-cloud-config-server8 CVEs
  43. 143.org.springframework:spring-expression8 CVEs
  44. 144.org.webjars.npm:jquery8 CVEs
  45. 145.org.yaml:snakeyaml8 CVEs
  46. 146.com.ctrip.framework.apollo:apollo7 CVEs
  47. 147.com.hazelcast:hazelcast7 CVEs
  48. 148.commons-fileupload:commons-fileupload7 CVEs
  49. 149.com.xuxueli:xxl-job-admin7 CVEs
  50. 150.io.atomix:atomix7 CVEs

Which Maven packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Book a Demo →