Maven — vulnerability landscape

Every CVE-affected package in the Maven ecosystem, sorted by risk.

Last updated 6/4/2026, 12:43:03 PM

#PackageCVEsKEVMax EPSS
1org.apache.tomcat.embed:tomcat-embed-core71594.5%
2org.apache.struts:struts2-core60594.4%
3org.jenkins-ci.main:jenkins-core251494.5%
4org.apache.tomcat:tomcat-catalina39394.4%
5org.elasticsearch:elasticsearch43292.3%
6org.apache.solr:solr-core30294.5%
7org.apache.activemq:activemq-client18294.4%
8org.geoserver.web:gs-web-app13294.4%
9org.apache.logging.log4j:log4j-core11294.4%
10org.geoserver:gs-wms8294.4%
11org.ops4j.pax.logging:pax-logging-log4j24294.4%
12com.thoughtworks.xstream:xstream37194.3%
13org.jenkins-ci.plugins:script-security35194.4%
14org.apache.tomcat:tomcat-coyote26194.4%
15org.springframework:spring-webmvc18194.4%
16org.apache.struts.xwork:xwork-core16193.6%
17org.jenkins-ci.plugins.workflow:workflow-cps13191.8%
18struts:struts11169.5%
19org.springframework:spring-webflux10194.4%
20org.apache.shiro:shiro-core10194.3%
21org.apache.activemq:activemq-broker9183.5%
22org.webjars.npm:jquery8134.7%
23org.apache.activemq:activemq-all8183.5%
24org.springframework.cloud:spring-cloud-config-server7194.3%
25org.apache.kylin:kylin-core-common6193.7%
26org.apache.struts:struts2-rest-plugin6194.3%
27io.netty:netty-codec-http26194.4%
28com.liferay.portal:com.liferay.portal.kernel6194.4%
29org.igniterealtime.openfire:xmppserver6194.4%
30com.typesafe.akka:akka-http-core_2.114194.4%
31org.eclipse.jetty.http2:jetty-http2-common4194.4%
32com.typesafe.akka:akka-http-core_2.124194.4%
33org.geoserver:gs-wfs4194.4%
34org.springframework.cloud:spring-cloud-gateway3194.5%
35org.springframework.data:spring-data-commons3194.3%
36org.richfaces:richfaces-core3189.5%
37org.eclipse.jetty.http2:http2-common3194.4%
38org.apache.activemq:activemq-openwire-legacy2194.4%
39org.xwiki.platform:xwiki-platform-search-solr-ui2193.7%
40org.apache.rocketmq:rocketmq-broker2194.4%
41org.eclipse.jetty.http2:http2-server2194.4%
42org.springframework:spring-beans2194.4%
43org.primefaces:primefaces2193.9%
44org.apache.spark:spark-parent_2.122193.5%
45org.springframework.cloud:spring-cloud-function-context2194.5%
46com.typesafe.akka:akka-http-core_2.132194.4%
47org.apache.hugegraph:hugegraph-api2194.3%
48org.apache.rocketmq:rocketmq-namesrv2194.4%
49com.typesafe.akka:akka-http-core2194.4%
50org.springframework.boot:spring-boot-starter-web1194.4%
51org.springframework.boot:spring-boot-starter-webflux1194.4%
52org.apache.rocketmq:rocketmq-controller1194.4%
53org.xbib.elasticsearch:log4j1194.4%
54uk.co.nichesolutions.logging.log4j:log4j-core1194.4%
55com.guicedee.services:log4j-core1194.4%
56org.apache.tomcat:tomcat-catalina-jmx-remote1193.8%
57org.apache.struts:struts2-struts1-plugin1194.1%
58it.geosolutions.jaiext.jiffle:jt-jiffle1194.0%
59org.eclipse.jetty.http2:jetty-http2-server1194.4%
60org.apache.hugegraph:hugegraph-core1194.3%
61org.apache.flink:flink-runtime_2.111194.3%
62org.sonatype.nexus:nexus-extdirect1194.4%
63org.apache.flink:flink-runtime_2.121194.3%
64it.geosolutions.jaiext.jiffle:jt-jiffle-language1194.0%
65org.zkoss.zk:zk1193.9%
66com.liferay.portal:release.portal.bom15979.6%
67org.apache.tomcat:tomcat15992.7%
68com.liferay.portal:release.dxp.bom12517.6%
69org.keycloak:keycloak-services7489.7%
70com.fasterxml.jackson.core:jackson-databind6984.9%
71org.keycloak:keycloak-core4992.3%
72org.xwiki.platform:xwiki-platform-oldcore4536.3%
73io.undertow:undertow-core3955.2%
74net.mingsoft:ms-mcms3975.5%
75com.jfinal:jfinal361.7%
76org.springframework.security:spring-security-core3190.2%
77org.opencms:opencms-core3118.6%
78org.eclipse.jetty:jetty-server2691.9%
79org.apache.openmeetings:openmeetings-parent2573.3%
80org.keycloak:keycloak-parent250.9%
81org.bouncycastle:bcprov-jdk14254.1%
82org.bouncycastle:bcprov-jdk15on2468.1%
83org.xwiki.platform:xwiki-platform-web-templates2370.7%
84org.apache.nifi:nifi213.9%
85org.cloudfoundry.identity:cloudfoundry-identity-server210.5%
86com.liferay.portal:com.liferay.portal.impl180.6%
87org.apache.jspwiki:jspwiki-main1850.6%
88org.springframework:spring-core1891.0%
89org.apache.inlong:manager-pojo177.1%
90org.apache.dolphinscheduler:dolphinscheduler1788.5%
91org.apache.geode:geode-core174.7%
92org.apache.ranger:ranger162.0%
93org.bouncycastle:bcprov-jdk15164.1%
94org.apache.dubbo:dubbo1689.0%
95io.netty:netty-codec-http1518.3%
96ai.h2o:h2o-core1563.3%
97org.xwiki.platform:xwiki-platform-web1538.8%
98org.jenkins-ci.plugins:git1381.3%
99org.apache.hadoop:hadoop-main134.6%
100org.apache.tika:tika-core1393.9%
101org.apache.kylin:kylin1393.3%
102org.jeecgframework.boot:jeecg-boot-parent1292.2%
103org.apache.cassandra:cassandra-all1291.0%
104org.apache.cxf:cxf-core128.6%
105org.apache.hadoop:hadoop-common123.0%
106org.bouncycastle:bcprov-jdk15to18124.1%
107org.apache.cxf:cxf1214.6%
108org.springframework:spring-web1260.4%
109org.apache.streampark:streampark126.6%
110org.graylog2:graylog2-server113.9%
111org.igniterealtime.openfire:parent1193.9%
112org.mortbay.jetty:jetty1119.4%
113org.apache.jspwiki:jspwiki-war114.4%
114org.apache.james:james-server1174.9%
115org.apache.camel:camel-core1128.7%
116com.xuxueli:xxl-job1119.0%
117org.xwiki.platform:xwiki-platform-rest-server1186.2%
118org.jenkins-ci.plugins:email-ext1120.6%
119org.xwiki.platform:xwiki-platform-administration-ui1192.5%
120org.apache.archiva:archiva1127.5%
121org.apache.commons:commons-compress111.8%
122org.apache.spark:spark-core_2.111089.0%
123io.netty:netty1018.3%
124org.jboss.netty:netty1018.3%
125org.jenkins-ci.plugins.workflow:workflow-cps-global-lib100.6%
126org.craftercms:crafter-studio1014.5%
127org.apache.inlong:manager-service100.9%
128org.apache.hive:hive-exec108.2%
129com.vaadin:flow-server101.8%
130org.apache.linkis:linkis101.4%
131com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer104.3%
132org.bouncycastle:bc-fips102.4%
133org.jenkins-ci.plugins:electricflow90.2%
134org.keycloak:keycloak-quarkus-server90.2%
135org.opencrx:opencrx-core-models90.4%
136org.postgresql:postgresql97.8%
137org.jenkins-ci.plugins:active-directory90.5%
138org.opennms:opennms92.4%
139mysql:mysql-connector-java963.8%
140io.jenkins:configuration-as-code90.1%
141cn.hutool:hutool-core90.6%
142org.apache.activemq:apache-activemq993.0%
143org.apache.xmlgraphics:batik947.8%
144org.apache.spark:spark-core_2.10989.0%
145com.vaadin:vaadin-bom90.7%
146org.apache.hive:hive91.0%
147org.bouncycastle:bcprov-jdk18on90.3%
148org.silverpeas.core:silverpeas-core-web96.7%
149org.jenkins-ci.plugins:config-file-provider90.8%
150org.apache.zookeeper:zookeeper917.4%
151org.apache.tapestry:tapestry-core994.2%
152org.jeecgframework.boot:jeecg-boot-common893.4%
153org.apache.santuario:xmlsec88.4%
154io.jenkins.blueocean:blueocean82.4%
155org.apache.ozone:ozone-main81.2%
156org.apache.wicket:wicket-core85.2%
157org.apache.zeppelin:zeppelin86.0%
158org.jenkins-ci.plugins:subversion83.7%
159io.netty:netty-handler88.2%
160ch.qos.logback:logback-core810.1%
161org.apache.hive:hive-service86.5%
162org.jenkins-ci.plugins:oic-auth80.5%
163org.yaml:snakeyaml893.8%
164com.ruoyi:ruoyi884.5%
165org.webjars:bootstrap89.8%
166org.apache.ambari:ambari82.5%
167org.jenkins-ci.plugins:ec280.7%
168org.apache.druid:druid893.9%
169org.apache.pdfbox:pdfbox813.0%
170io.vertx:vertx-core71.3%
171io.vertx:vertx-web72.5%
172net.opentsdb:opentsdb794.3%
173com.hazelcast:hazelcast78.3%
174org.jenkins-ci.plugins:artifactory70.3%
175ca.uhn.hapi.fhir:org.hl7.fhir.utilities77.9%
176org.owasp.antisamy:antisamy70.7%
177org.jboss.resteasy:resteasy-client74.6%
178ca.uhn.hapi.fhir:org.hl7.fhir.r577.9%
179org.opensearch.plugin:opensearch-security70.4%
180org.opencastproject:opencast-kernel70.3%
181org.jeecgframework.boot:jeecg-boot-base757.2%
182org.apache.poi:poi713.1%
183io.jenkins.plugins:cavisson-ns-nd-integration79.5%
184ca.uhn.hapi.fhir:org.hl7.fhir.r4b77.9%
185io.jenkins.plugins:miniorange-saml-sp70.6%
186org.jenkins-ci.plugins:credentials-binding72.7%
187io.dataease:dataease-plugin-common70.9%
188io.atomix:atomix70.4%
189org.apache.mina:mina-core755.9%
190org.apache.axis:axis790.0%
191org.apache.karaf:apache-karaf75.4%
192org.jruby:jruby-stdlib71.8%
193org.apache.kafka:kafka-clients721.4%
194com.xuxueli:xxl-job-admin71.3%
195org.apache.inlong:manager-web70.9%
196org.jenkins-ci.plugins:rundeck70.4%
197org.jenkins-ci.plugins:mercurial70.5%
198tech.powerjob:powerjob790.4%
199org.jenkins-ci.plugins:jobConfigHistory716.3%
200org.apache.derby:derby72.6%
201org.apache.cxf:apache-cxf714.6%
202org.jenkins-ci.plugins:htmlpublisher71.3%
203commons-fileupload:commons-fileupload792.7%
204org.apache.atlas:atlas-common71.9%
205org.webjars.npm:jquery-ui731.2%
206org.apache.activemq:activemq-parent765.7%
207org.jenkins-ci.plugins:openshift-deployer70.3%
208org.apache.syncope:syncope-core77.1%
209net.gleske:jervis70.1%
210io.jenkins.plugins:warnings-ng70.8%
211log4j:log4j672.2%
212org.apache.streampipes:streampipes-parent61.8%
213org.apache.storm:storm-core615.3%
214org.jenkins-ci.plugins:azure-ad60.9%
215org.jenkins-ci.plugins:azure-vm-agents60.4%
216org.apache.solr:solr-parent693.9%
217org.pytorch:executorch-android60.4%
218ca.uhn.hapi.fhir:org.hl7.fhir.validation67.9%
219axis:axis690.0%
220org.apache.struts:struts-core669.5%
221org.silverpeas.core:silverpeas-core649.8%
222com.google.protobuf:protobuf-java60.5%
223org.infinispan:infinispan-core61.8%
224org.hibernate:hibernate-validator61.7%
225org.apache.pulsar:pulsar-broker60.3%
226cn.hutool:hutool-json61.2%
227org.apache.shenyu:shenyu-common689.9%
228org.apache.mesos:mesos64.9%
229org.jeecgframework.boot:jeecg-boot-base-core61.1%
230com.xuxueli:xxl-job-core626.9%
231gov.nsa.emissary:emissary60.1%
232org.csanchez.jenkins.plugins:kubernetes61.5%
233com.vaadin:vaadin-server60.7%
234com.xebialabs.deployit.ci:deployit-plugin60.1%
235org.jenkins-ci.plugins:repository-connector616.8%
236org.apache.ignite:ignite-core65.6%
237org.apache.httpcomponents:httpclient64.4%
238org.jenkins-ci.plugins:pipeline-maven60.4%
239com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger60.2%
240org.yamcs:yamcs-core6
241com.datapipe.jenkins.plugins:hashicorp-vault-plugin60.7%
242com.nimbusds:nimbus-jose-jwt64.3%
243org.jenkins-ci.plugins:ghprb60.3%
244org.apache.zeppelin:zeppelin-server60.9%
245org.jenkins-ci.plugins:fortify-on-demand-uploader60.5%
246org.wildfly:wildfly-parent630.0%
247org.xwiki.commons:xwiki-commons-xml621.6%
248org.jenkins-ci.plugins:gitlab-oauth60.1%
249com.jflyfox:jflyfox_jfinal64.1%
250net.snowflake:snowflake-jdbc62.1%
251org.apache.tika:tika60.4%
252org.jenkins-ci.plugins:ec2-deployment-dashboard69.1%
253org.jenkins-ci.plugins:gitlab-plugin614.9%
254hudson.plugins:project-inheritance69.1%
255org.xwiki.platform:xwiki-platform-flamingo-skin-resources648.1%
256org.springframework.security.oauth:spring-security-oauth2593.7%
257org.jenkins-ci.plugins:codedx50.5%
258org.springframework.security:spring-security-config549.3%
259org.springframework.boot:spring-boot50.6%
260org.springframework.amqp:spring-amqp521.3%
261org.owasp.esapi:esapi51.0%
262org.jeecgframework.boot:jeecg-module-system51.1%
263org.jenkins-ci.plugins:credentials50.4%
264io.projectreactor.netty:reactor-netty-http51.5%
265org.jenkins-ci.plugins:aws-codecommit-trigger50.6%
266org.springframework.security:spring-security-web590.2%
267io.jenkins.plugins:neuvector-vulnerability-scanner51.1%
268org.jboss.resteasy:resteasy-bom52.3%
269org.open-metadata:openmetadata-service592.9%
270org.opennms:opennms-webapp50.5%
271org.geoserver:gs-main593.3%
272org.fitnesse:fitnesse56.6%
273org.keycloak:keycloak-server-spi-private50.3%
274ca.uhn.hapi.fhir:org.hl7.fhir.r457.9%
275info.magnolia:magnolia-core51.2%
276org.glassfish.main.admingui:console-common50.4%
277org.opencastproject:opencast-common50.4%
278edu.stanford.nlp:stanford-corenlp50.5%
279org.jenkins-ci.plugins:wso2id-oauth50.4%
280org.dspace:dspace-jspui50.8%
281org.jenkins-ci.tools:git-parameter50.2%
282org.jenkins-ci.plugins:websphere-deployer50.1%
283org.jenkins-ci.plugins:vmanager-plugin50.9%
284org.jenkins-ci.plugins:sinatra-chef-builder50.1%
285org.apache.kylin:kylin-server-base584.7%
286ca.uhn.hapi.fhir:org.hl7.fhir.dstu357.9%
287org.jenkins-ci.plugins:support-core50.8%
288ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may57.9%
289com.vaadin:vaadin50.4%
290org.apache.inlong:manager-dao50.9%
291org.apache.iotdb:iotdb-core53.4%
292org.codehaus.jettison:jettison50.5%
293org.jenkins-ci.plugins:publish-over-ssh51.3%
294org.jenkins-ci.plugins:scriptler50.2%
295org.apache.hadoop:hadoop-client55.8%
296org.jenkinsci.plugins:octoperf50.6%
297com.synopsys.jenkinsci:ownership50.2%
298com.shopizer:shopizer50.7%
299org.jenkins-ci.plugins:matrix-project59.0%
300com.alibaba:dubbo574.6%