Maven Package Vulnerabilities
All 3,122 Java / JVM artifacts with known CVEs, ranked by live CVE volume — 8,137 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 301.org.opennms:opennms-webapp5 CVEs
- 302.org.owasp.esapi:esapi5 CVEs
- 303.org.springframework.boot:spring-boot5 CVEs
- 304.org.springframework.security.oauth:spring-security-oauth25 CVEs
- 305.org.springframework.security:spring-security-config5 CVEs
- 306.org.wildfly.security:wildfly-elytron5 CVEs
- 307.org.xwiki.platform:xwiki-platform-appwithinminutes-ui5 CVEs
- 308.org.xwiki.platform:xwiki-platform-distribution-war5 CVEs
- 309.org.xwiki.platform:xwiki-platform-legacy-oldcore5 CVEs
- 310.org.xwiki.platform:xwiki-platform-livetable-ui5 CVEs
- 311.org.zenframework.z8.dependencies.commons:log4j-1.2.175 CVEs
- 312.xerces:xercesImpl5 CVEs
- 313.ca.uhn.hapi.fhir:org.hl7.fhir.core4 CVEs
- 314.ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli4 CVEs
- 315.com.alibaba:fastjson4 CVEs
- 316.com.alibaba.nacos:nacos-common4 CVEs
- 317.com.amazon.redshift:redshift-jdbc424 CVEs
- 318.com.arcadedb:arcadedb-engine4 CVEs
- 319.com.bstek.ureport:ureport2-core4 CVEs
- 320.com.caucho:resin4 CVEs
- 321.com.checkmarx.jenkins:checkmarx4 CVEs
- 322.com.cloudtp.jenkins:paaslane-estimate4 CVEs
- 323.com.compuware.jenkins:compuware-topaz-for-total-test4 CVEs
- 324.com.convertigo.jenkins.plugins:convertigo-mobile-platform4 CVEs
- 325.com.elasticbox.jenkins-ci.plugins:kubernetes-ci4 CVEs
- 326.com.github.junrar:junrar4 CVEs
- 327.com.google.protobuf:protobuf-javalite4 CVEs
- 328.com.h2database:h24 CVEs
- 329.com.hubspot.jinjava:jinjava4 CVEs
- 330.com.itextpdf:itext7-core4 CVEs
- 331.com.liferay:com.liferay.change.tracking.web4 CVEs
- 332.com.liferay:com.liferay.dynamic.data.mapping.form.field.type4 CVEs
- 333.com.liferay:com.liferay.frontend.taglib.clay4 CVEs
- 334.com.liferay:com.liferay.portal.vulcan.impl4 CVEs
- 335.com.mchange:c3p04 CVEs
- 336.com.surenpi.jenkins:phoenix-autotest4 CVEs
- 337.com.typesafe.akka:akka-http-core_2.114 CVEs
- 338.com.typesafe.akka:akka-http-core_2.124 CVEs
- 339.com.typesafe.play:play4 CVEs
- 340.com.typesafe.play:play_2.124 CVEs
- 341.io.crate:crate4 CVEs
- 342.io.goobi.viewer:viewer-core4 CVEs
- 343.io.hawt:project4 CVEs
- 344.io.jenkins.plugins:macstadium-orka4 CVEs
- 345.io.netty:netty-codec-http34 CVEs
- 346.io.ratpack:ratpack-core4 CVEs
- 347.io.strimzi:strimzi4 CVEs
- 348.io.swagger:swagger-codegen4 CVEs
- 349.io.undertow:undertow-parent4 CVEs
- 350.net.minidev:json-smart4 CVEs
Which Maven packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →