Maven Package Vulnerabilities

All 3,086 Java / JVM artifacts with known CVEs, ranked by live CVE volume — 7,979 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.

  1. 701.com.liferay:com.liferay.organizations.item.selector.web2 CVEs
  2. 702.com.liferay:com.liferay.portal.security.ldap.impl2 CVEs
  3. 703.com.liferay:com.liferay.portal.workflow.kaleo.designer.web2 CVEs
  4. 704.com.liferay:com.liferay.portal.workflow.kaleo.forms.web2 CVEs
  5. 705.com.liferay:com.liferay.server.admin.web2 CVEs
  6. 706.com.liferay:com.liferay.site.admin.web2 CVEs
  7. 707.com.liferay:com.liferay.translation.web2 CVEs
  8. 708.com.liferay.portal:com.liferay.util.java2 CVEs
  9. 709.com.liferay.portal:portal-impl2 CVEs
  10. 710.com.liferay.portal:portal-service2 CVEs
  11. 711.com.meowlomo.jenkins:scm-httpclient2 CVEs
  12. 712.commons-io:commons-io2 CVEs
  13. 713.com.nepxion:discovery2 CVEs
  14. 714.com.ning:async-http-client2 CVEs
  15. 715.com.okta.sdk:okta-sdk-root2 CVEs
  16. 716.com.ongres.scram:scram-common2 CVEs
  17. 717.com.openmake:deployhub2 CVEs
  18. 718.com.openshift.jenkins:openshift-pipeline2 CVEs
  19. 719.com.opensymphony:xwork2 CVEs
  20. 720.com.orientechnologies:orientdb-studio2 CVEs
  21. 721.com.paul8620.jenkins.plugins:pipeline-aggregator-view2 CVEs
  22. 722.com.powsybl:powsybl-commons2 CVEs
  23. 723.com.puppycrawl.tools:checkstyle2 CVEs
  24. 724.com.qualys.plugins:qualys-pc2 CVEs
  25. 725.com.qualys.plugins:qualys-was2 CVEs
  26. 726.com.rabbitmq:amqp-client2 CVEs
  27. 727.com.redgate.plugins.redgatesqlci:redgate-sql-ci2 CVEs
  28. 728.com.sap.cloud.security:java-security2 CVEs
  29. 729.com.sap.cloud.security:spring-security2 CVEs
  30. 730.com.sap.cloud.security.xsuaa:spring-xsuaa2 CVEs
  31. 731.com.softwaremill.akka-http-session:core_2.122 CVEs
  32. 732.com.sonyericsson.hudson.plugins.rebuild:rebuild2 CVEs
  33. 733.com.sparkjava:spark-core2 CVEs
  34. 734.com.squareup.okhttp3:okhttp2 CVEs
  35. 735.com.squareup.retrofit2:retrofit2 CVEs
  36. 736.com.squareup.wire:wire-runtime2 CVEs
  37. 737.com.typesafe.akka:akka-http-core2 CVEs
  38. 738.com.typesafe.akka:akka-http-core_2.132 CVEs
  39. 739.com.typesafe.play:play_2.132 CVEs
  40. 740.com.typesafe.play:play-java2 CVEs
  41. 741.com.veracode.jenkins:veracode-scan2 CVEs
  42. 742.com.xebialabs.xlt.ci:xltestview-plugin2 CVEs
  43. 743.com.xuxueli:xxl-rpc-core2 CVEs
  44. 744.com.xuxueli:xxl-sso2 CVEs
  45. 745.com.xwiki.confluencepro:application-confluence-migrator-pro-ui2 CVEs
  46. 746.com.zintow:dingding-json-pusher2 CVEs
  47. 747.de.einsundeins.jenkins.plugins.failedjobdeactivator:failedJobDeactivator2 CVEs
  48. 748.dev.dsf:dsf-bpe-server2 CVEs
  49. 749.de.wellnerbou.jenkins:git-changelog2 CVEs
  50. 750.dom4j:dom4j2 CVEs

Which Maven packages run in YOUR stack?

EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.

Start Free Scan →