maven
562,657 packages · repo1.maven.org
Security Advisories in maven
      
        Moderate
      
    
      
  
          3 days ago
    
    Liferay Portal and DXP do not check permissions of images in a blog entry
        
        maven
        
        com.liferay:com.liferay.blogs.item.selector.web
      
    
      
        Moderate
      
    
      
  
          3 days ago
    
    Liferay Portal and DXP use an incorrect cache-control header
        
        maven
        
        com.liferay.portal:com.liferay.portal.impl, com.liferay:com.liferay.adaptive.media.web
      
    
      
        Moderate
      
    
      
  
          3 days ago
    
    Liferay Portal and DXP affected by multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page
        
        maven
        
        com.liferay:com.liferay.dynamic.data.mapping.item.selector.web
      
    
      
        Moderate
      
    
      
  
          3 days ago
    
    Liferay Portal Vulnerable to Reflected XSS via the selectedLanguageId Parameter
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          4 days ago
    
    Liferay Portal is vulnerable to XSS in the Blogs widget
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          4 days ago
    
    Liferay Portal is vulnerable to DNS rebinding attacks
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Liferay Portal vulnerable to password enumeration
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Publish to Bitbucket Plugin is missing a permissions check
        
        maven
        
        org.jenkins-ci.plugins:publish-to-bitbucket
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Publish to Bitbucket Plugin is missing a permissions check
        
        maven
        
        org.jenkins-ci.plugins:publish-to-bitbucket
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check
        
        maven
        
        org.jenkins-ci.plugins:publish-to-bitbucket
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Curseforge Publisher Plugin does not mask API Keys displayed on the job configuration form
        
        maven
        
        org.jenkins-ci.plugins:curseforge-publisher
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
        
        maven
        
        io.jenkins.plugins:mcp-server
      
    
      
        High
      
    
      
  
          5 days ago
    
    Jenkins Azure CLI Plugin does not restrict the commands it executes
        
        maven
        
        org.jenkins-ci.plugins:azure-cli
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins ByteGuard Build Actions Plugin does not mask API tokens displayed on the job configuration form
        
        maven
        
        io.jenkins.plugins:byteguard-build-actions
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Nexus Task Runner Plugin vulnerable to cross-site request forgery
        
        maven
        
        org.jenkins-ci.plugins:nexus-task-runner
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Eggplant Runner Plugin protection mechanism disabled
        
        maven
        
        io.jenkins.plugins:eggplant-runner
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Nexus Task Runner Plugin is missing a permission check
        
        maven
        
        org.jenkins-ci.plugins:nexus-task-runner
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Themis Plugin is missing a permission check
        
        maven
        
        org.jenkins-ci.plugins:themis
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Start Windocks Containers Plugin is missing a permission check
        
        maven
        
        org.jenkins-ci.plugins:windocks-start-container
      
    
      
        High
      
    
      
  
          5 days ago
    
    Jenkins JDepend Plugin vulnerable to XML external entity attacks
        
        maven
        
        org.jenkins-ci.plugins:jdepend
      
    
      
        High
      
    
      
  
          5 days ago
    
    Jenkins SAML Plugin does not implement a replay cache
        
        maven
        
        org.jenkins-ci.plugins:saml
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins OpenShift Pipeline Plugin stores authorization tokens unencrypted in job config.xml files
        
        maven
        
        com.openshift.jenkins:openshift-pipeline
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files
        
        maven
        
        io.jenkins.plugins:byteguard-build-actions
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Themis Plugin vulnerable to cross-site request forgery
        
        maven
        
        org.jenkins-ci.plugins:themis
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Curseforge Publisher Plugin stores API Keys unencrypted in job config.xml files
        
        maven
        
        org.jenkins-ci.plugins:curseforge-publisher
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Start Windocks Containers Plugin vulnerable to cross-site request forgery
        
        maven
        
        org.jenkins-ci.plugins:windocks-start-container
      
    
      
        Moderate
      
    
      
  
          5 days ago
    
    Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery
        
        maven
        
        jp.ikedam.jenkins.plugins:extensible-choice-parameter
      
    
      
        Moderate
      
    
      
  
          6 days ago
    
    InventoryGui allows item duplication in GUIs which use GuiStorageElement
        
        maven
        
        de.themoep:inventorygui
      
    
      
        Moderate
      
    
      
  
          6 days ago
    
    Keycloak vulnerable to session takeovers due to reuse of session identifiers
        
        maven
        
        org.keycloak:keycloak-services
      
    
      
        Low
      
    
      
  
          7 days ago
    
    Keycloak allows access to admin path through flaw
        
        maven
        
        org.keycloak:keycloak-quarkus-server
      
    
      
        High
      
    
      
  
          7 days ago
    
    Liferay Portal Vulnerable to CSRF in Headless APIs
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          7 days ago
    
    Liferay Portal Does Not Limit Access to APIs Before Email Verification
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        High
      
    
      
  
          7 days ago
    
    Liferay Portal Vulnerable to DoS via Crafted Headless API Request
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          7 days ago
    
    Liferay Portal Stores Password Reset Tokens in Plain Text
        
        maven
        
        com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          7 days ago
    
    Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature
        
        maven
        
        com.liferay:com.liferay.portal.security.ldap.impl
      
    
      
        Moderate
      
    
      
  
          7 days ago
    
    Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter
        
        maven
        
        com.liferay:com.liferay.layout.admin.web
      
    
      
        Moderate
      
    
      
  
          7 days ago
    
    Liferay Portal Vulnerable to Cross-Site Scripting
        
        maven
        
        com.liferay:com.liferay.account.admin.web
      
    
      
        High
      
    
      
  
          7 days ago
    
    Keycloak TLS Client-Initiated Renegotiation Denial of Service
        
        maven
        
        org.keycloak:keycloak-quarkus-dist
      
    
      
        Moderate
      
    
      
  
          7 days ago
    
    InventoryGui allows item duplication with experimental "Bundle" item in GUIs which use GuiStorageElement
        
        maven
        
        de.themoep:inventorygui
      
    
      
        Moderate
      
    
      
  
          7 days ago
    
    InventoryGui affected by item duplication in GUIs which use GuiStorageElement
        
        maven
        
        de.themoep:inventorygui
      
    
      
        Low
      
    
      
  
          7 days ago
    
    Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
        
        maven
        
        org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat
      
    
      
        High
      
    
      
  
          7 days ago
    
    Apache Tomcat Vulnerable to Relative Path Traversal
        
        maven
        
        org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat
      
    
      
        Low
      
    
      
  
          7 days ago
    
    Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
        
        maven
        
        org.apache.tomcat:tomcat-catalina, org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
      
    
      
        Moderate
      
    
      
  
          10 days ago
    
    Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
        
        maven
        
        org.bouncycastle:bcprov-debug-lts8on, org.bouncycastle:bc-fips
      
    
      
        Moderate
      
    
      
  
          11 days ago
    
    Liferay Portal ComboServlet denial of service via large file combination
        
        maven
        
        com.liferay.portal:com.liferay.portal.impl
      
    
      
        Moderate
      
    
      
  
          11 days ago
    
    MCMS reflected cross-site scripting (XSS) vulnerability
        
        maven
        
        net.mingsoft:ms-mcms
      
    
      
        Low
      
    
      
  
          11 days ago
    
    Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page
        
        maven
        
        com.liferay:com.liferay.knowledge.base.web
      
    
      
        Moderate
      
    
      
  
          11 days ago
    
    Keycloak does not invalidate sessions when "Remember Me" is disabled
        
        maven
        
        org.keycloak:keycloak-services
      
    
      
        Moderate
      
    
      
  
          11 days ago
    
    Liferay Portal and DXP do not properly restrict access to OpenAPI
        
        maven
        
        com.liferay:com.liferay.portal.security.auth.verifier
      
    
      
        Moderate
      
    
      
  
          11 days ago
    
    Keycloak does not invalidate offline sessions when the offline_access scope is removed
        
        maven
        
        org.keycloak:keycloak-services
      
    
      
        Low
      
    
      
  
          12 days ago
    
    Liferay Portal and DXP are Missing Authorization in Collection Provider
        
        maven
        
        com.liferay:com.liferay.search.experiences.service
      
    
      
        Moderate
      
    
      
  
          12 days ago
    
    Liferay Portal and Liferay DXP vulnerable to reflected cross-site scripting (XSS)
        
        maven
        
        com.liferay:com.liferay.dynamic.data.mapping.web
      
    
      
        Moderate
      
    
      
  
          12 days ago
    
    Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl
        
        maven
        
        org.sakaiproject.kernel:sakai-kernel-impl
      
    
      
        Low
      
    
      
  
          12 days ago
    
    Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
        
        maven
        
        io.vertx:vertx-web
      
    
      
        Moderate
      
    
      
  
          12 days ago
    
    Vert.x-Web Access Control Flaw in StaticHandler’s Hidden File Protection for Files Under Hidden Directories
        
        maven
        
        io.vertx:vertx-web
      
    
      
        Moderate
      
    
      
  
          13 days ago
    
    Liferay Portal reflected cross-site scripting (XSS) vulnerability in the google_gaget
        
        maven
        
        com.liferay.portal:com.liferay.portal.impl
      
    
      
        Moderate
      
    
      
  
          13 days ago
    
    Liferay Portal fails to verify messages from the cluster network is trusted
        
        maven
        
        com.liferay:com.liferay.portal.cluster.multiple
      
    
      
        High
      
    
      
  
          14 days ago
    
    Apache Syncope allows malicious administrators to inject Groovy code
        
        maven
        
        org.apache.syncope.core:syncope-core-spring
      
    
      
        High
      
    
      
  
          16 days ago
    
    Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
        
        maven
        
        org.apache.geode:geode-web
      
    
      
        Critical
      
    
      
  
          17 days ago
    
    MCMS vulnerable SQL injection via the content_title parameter
        
        maven
        
        net.mingsoft:ms-mcms
      
    
      
        Moderate
      
    
      
  
          17 days ago
    
    Keycloak error_description injection on error pages that can trigger phishing attacks
        
        maven
        
        org.keycloak:keycloak-admin-ui, org.keycloak:keycloak-account-ui
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    Mammoth is vulnerable to Directory Traversal
        
        nuget, pypi, maven, npm
        
        Mammoth, mammoth, org.zwobble.mammoth:mammoth
      
    
      
        High
      
    
      
  
          18 days ago
    
    Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
        
        maven
        
        org.springframework.cloud:spring-cloud-gateway-server-webflux
      
    
      
        Moderate
      
    
      
  
          18 days ago
    
    Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
        
        maven
        
        org.springframework:spring-websocket
      
    
      
        Moderate
      
    
      
  
          19 days ago
    
    GeoIP processor disables SSL certificate validation when downloading databases
        
        maven
        
        org.opensearch.dataprepper.plugins:geoip-processor
      
    
      
        Moderate
      
    
      
  
          19 days ago
    
    OpenSearch Data Prepper uses deprecated SSL protocol identifier
        
        maven
        
        org.opensearch.dataprepper.plugins:geoip-processor
      
    
      
        High
      
    
      
  
          19 days ago
    
    OpenSearch Data Prepper plugins trust all SSL certificates by default
        
        maven
        
        org.opensearch.dataprepper.plugins:opensearch
      
    
      
        High
      
    
      
  
          19 days ago
    
    Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
        
        maven
        
        io.netty:netty-codec-smtp
      
    
      
        Moderate
      
    
      
  
          20 days ago
    
    Apache Spark has Inadequate Encryption Strength
        
        maven
        
        org.apache.spark:spark-network-common_2.12, org.apache.spark:spark-network-common_2.13
      
    
      
        High
      
    
      
  
          20 days ago
    
    JDBC Driver for SQL Server has improper input validation issue
        
        maven
        
        com.microsoft.sqlserver:mssql-jdbc
      
    
      
        Moderate
      
    
      
  
          20 days ago
    
    Apache Geode web-api is vulnerable to Cross-site Scripting
        
        maven
        
        org.apache.geode:geode-web-api
      
    
      
        Moderate
      
    
      
  
          21 days ago
    
    Liferay has Incorrect Permission Assignment for Critical Resource
        
        maven
        
        com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary
      
    
      
        Moderate
      
    
      
  
          21 days ago
    
    Liferay Mentions Web is Vulnerable to Cross-site Scripting
        
        maven
        
        com.liferay:com.liferay.mentions.web
      
    
      
        Moderate
      
    
      
  
          21 days ago
    
    Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key
        
        maven
        
        com.liferay.portal:com.liferay.portal.impl
      
    
      
        Moderate
      
    
      
  
          21 days ago
    
    Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
        
        maven
        
        com.liferay.commerce:com.liferay.commerce.order.content.web
      
    
      
        Moderate
      
    
      
  
          21 days ago
    
    Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
        
        maven
        
        com.liferay:com.liferay.change.tracking.web
      
    
      
        Moderate
      
    
      
  
          21 days ago
    
    Liferay Publications is vulnerable to Incorrect Authorization
        
        maven
        
        com.liferay:com.liferay.change.tracking.web
      
    
      
        Moderate
      
    
      
  
          21 days ago
    
    Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key
        
        maven
        
        com.liferay:com.liferay.change.tracking.web
      
    
      
        Moderate
      
    
      
  
          24 days ago
    
    Liferay Portal is vulnerable to CSRF through publication comments
        
        maven
        
        com.liferay:com.liferay.change.tracking.web
      
    
      
        Moderate
      
    
      
  
          24 days ago
    
    PowerJob OpenAPIController is missing authorization
        
        maven
        
        tech.powerjob:powerjob-server-starter
      
    
      
        Moderate
      
    
      
  
          24 days ago
    
    Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
        
        maven
        
        com.liferay:com.liferay.account.admin.web
      
    
      
        Moderate
      
    
      
  
          24 days ago
    
    Liferay Portal Commerce is vulnerable to XSS through account "name" field
        
        maven
        
        com.liferay.commerce:com.liferay.commerce.order.web
      
    
      
        Moderate
      
    
      
  
          24 days ago
    
    Liferay Portal is vulnerable to XSS through its workflow process builder
        
        maven
        
        com.liferay:com.liferay.portal.workflow.kaleo.designer.web
      
    
      
        Moderate
      
    
      
  
          24 days ago
    
    Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
        
        maven
        
        org.elasticsearch:elasticsearch
      
    
      
        High
      
    
      
  
          24 days ago
    
    Apache StreamPark contains an Incorrect Execution-Assigned Permissions vulnerability
        
        maven
        
        org.apache.streampark:streampark
      
    
      
        Moderate
      
    
      
  
          25 days ago
    
    Liferay Portal is vulnerable to XSS through its Calendar Events parameters
        
        maven
        
        com.liferay:com.liferay.calendar.web
      
    
      
        Moderate
      
    
      
  
          25 days ago
    
    Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers
        
        maven
        
        org.apache.flink:flink-connector-mysql-cdc, org.apache.flink:flink-connector-sqlserver-cdc, org.apache.flink:flink-connector-db2-cdc, org.apache.flink:flink-connector-oracle-cdc, org.apache.flink:flink-cdc-pipeline-connectors
      
    
      
        Moderate
      
    
      
  
          26 days ago
    
    Keycloak Potential Variable Reference in Model Storage Services
        
        maven
        
        org.keycloak:keycloak-model-storage-services
      
    
      
        Moderate
      
    
      
  
          26 days ago
    
    Opencast's Paella Player 7 is vulnerable to Cross-Site Scripting
        
        maven
        
        org.opencastproject:opencast-common
      
    
      
        Moderate
      
    
      
  
          26 days ago
    
    Liferay Portal Notifications Widget has multiple XSS vulnerabilities through various text fields
        
        maven
        
        com.liferay:com.liferay.flags.web
      
    
      
        Moderate
      
    
      
  
          26 days ago
    
    Liferay Portal is vulnerable to Stored XSS through Forms text type field
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          26 days ago
    
    Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG file
        
        maven
        
        com.liferay.commerce:com.liferay.commerce.shop.by.diagram.web
      
    
      
        Moderate
      
    
      
  
          26 days ago
    
    Liferay Portal is vulnerable to XXS through its Commerce Product's Name text field
        
        maven
        
        com.liferay.commerce:com.liferay.commerce.product.service
      
    
      
        Moderate
      
    
      
  
          27 days ago
    
    Liferay Portal has multiple Stored XSS vulnerabilities on its View Order page
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          27 days ago
    
    Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Moderate
      
    
      
  
          28 days ago
    
    Liferay Profile Widget does not prevent vCard extension spoofing
        
        maven
        
        com.liferay.portal:release.portal.bom
      
    
      
        Critical
      
    
      
  
          28 days ago
    
    XWiki Platform is vulnerable to HQL injection via wiki and space search REST API
        
        maven
        
        org.xwiki.platform:xwiki-platform-rest-server
      
    
      
        Critical
      
    
      
  
          28 days ago
    
    XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
        
        maven
        
        org.xwiki.contrib.oidc:oidc-authenticator
      
    
      
        Moderate
      
    
      
  
          about 1 month ago
    
    Liferay Portal exposes sensitive user data through its Freemarker template
        
        maven
        
        com.liferay:com.liferay.portal.template.freemarker
      
    
      
        High
      
    
      
  
          about 1 month ago
    
    Apache Kylin Files or Directories Accessible to External Parties
        
        maven
        
        org.apache.kylin:kylin-server, org.apache.kylin:kylin-ops-server, org.apache.kylin:kylin-core-metadata, org.apache.kylin:kylin-core-common, org.apache.kylin:kylin-common-service, org.apache.kylin:kylin-common-server, org.apache.kylin:kylin
      
    Filter by Severity
Filter by Package
          
            org.jenkins-ci.main:jenkins-core
            242
          
            com.liferay.portal:release.portal.bom
            159
          
            org.apache.tomcat:tomcat
            135
          
            com.liferay.portal:release.dxp.bom
            117
          
            com.fasterxml.jackson.core:jackson-databind
            69
          
            org.apache.struts:struts2-core
            55
          
            org.keycloak:keycloak-core
            50
          
            org.keycloak:keycloak-services
            45
          
            org.xwiki.platform:xwiki-platform-oldcore
            43
          
            org.elasticsearch:elasticsearch
            43
          
            org.apache.tomcat.embed:tomcat-embed-core
            40
          
            net.mingsoft:ms-mcms
            38
          
            com.thoughtworks.xstream:xstream
            37
          
            com.jfinal:jfinal
            36
          
            io.undertow:undertow-core
            35
          
            org.jenkins-ci.plugins:script-security
            33
          
            org.apache.solr:solr-core
            28
          
            org.opencms:opencms-core
            27
          
            org.apache.tomcat:tomcat-catalina
            26
          
            org.springframework.security:spring-security-core
            26
          
            org.eclipse.jetty:jetty-server
            25
          
            org.keycloak:keycloak-parent
            24
          
            org.apache.openmeetings:openmeetings-parent
            22
          
            org.bouncycastle:bcprov-jdk15on
            21
          
            org.apache.nifi:nifi
            21
          
            org.cloudfoundry.identity:cloudfoundry-identity-server
            20
          
            org.xwiki.platform:xwiki-platform-web-templates
            20
          
            org.apache.tomcat:tomcat-coyote
            18
          
            com.liferay.portal:com.liferay.portal.impl
            18
          
            org.springframework:spring-core
            18
          
            com.vaadin:vaadin-bom
            18
          
            org.apache.jspwiki:jspwiki-main
            18
          
            org.apache.geode:geode-core
            17
          
            org.apache.inlong:manager-pojo
            17
          
            org.apache.dubbo:dubbo
            16
          
            org.apache.activemq:activemq-client
            16
          
            org.apache.ranger:ranger
            16
          
            org.springframework:spring-webmvc
            14
          
            org.xwiki.platform:xwiki-platform-web
            14
          
            org.apache.hadoop:hadoop-main
            13
          
            org.apache.dolphinscheduler:dolphinscheduler
            13
          
            org.apache.kylin:kylin
            13
          
            org.apache.struts.xwork:xwork-core
            13
          
            ai.h2o:h2o-core
            13
          
            org.apache.cxf:cxf-core
            13
          
            org.graylog2:graylog2-server
            12
          
            org.jeecgframework.boot:jeecg-boot-parent
            12
          
            org.apache.hadoop:hadoop-common
            12
          
            h2o
            12
          
            com.vaadin:flow-server
            12
          
            org.jenkins-ci.plugins.workflow:workflow-cps
            12
          
            org.apache.tika:tika-core
            12
          
            org.springframework:spring-web
            12
          
            org.jenkins-ci.plugins:git
            12
          
            org.apache.camel:camel-core
            11
          
            org.apache.james:james-server
            11
          
            org.apache.archiva:archiva
            11
          
            org.igniterealtime.openfire:parent
            11
          
            org.apache.jspwiki:jspwiki-war
            11
          
            org.xwiki.platform:xwiki-platform-administration-ui
            11
          
            org.mortbay.jetty:jetty
            11
          
            org.jenkins-ci.plugins:email-ext
            11
          
            com.xuxueli:xxl-job
            11
          
            org.apache.commons:commons-compress
            11
          
            org.jenkins-ci.plugins.workflow:workflow-cps-global-lib
            10
          
            org.geoserver.web:gs-web-app
            10
          
            org.opensearch.plugin:opensearch-security
            10
          
            org.craftercms:crafter-studio
            10
          
            com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
            10
          
            org.apache.cxf:cxf
            10
          
            io.netty:netty
            9
          
            org.apache.shiro:shiro-core
            9
          
            org.apache.linkis:linkis
            9
          
            cn.hutool:hutool-core
            9
          
            org.apache.streampark:streampark
            9
          
            org.opennms:opennms
            9
          
            io.jenkins:configuration-as-code
            9
          
            org.jboss.netty:netty
            9
          
            org.apache.cassandra:cassandra-all
            9
          
            org.apache.inlong:manager-service
            9
          
            org.opencrx:opencrx-core-models
            9
          
            struts:struts
            9
          
            org.apache.hive:hive
            9
          
            org.bouncycastle:bcprov-jdk14
            9
          
            org.apache.hive:hive-exec
            9
          
            org.apache.tapestry:tapestry-core
            9
          
            org.jenkins-ci.plugins:electricflow
            9
          
            org.jenkins-ci.plugins:config-file-provider
            9
          
            org.jenkins-ci.plugins:active-directory
            9
          
            org.postgresql:postgresql
            9
          
            org.xwiki.platform:xwiki-platform-rest-server
            9
          
            org.jenkins-ci.plugins:subversion
            8
          
            org.apache.ozone:ozone-main
            8
          
            org.silverpeas.core:silverpeas-core-web
            8
          
            org.apache.xmlgraphics:batik
            8
          
            org.jenkins-ci.plugins:ec2
            8
          
            org.jeecgframework.boot:jeecg-boot-common
            8
          
            org.jenkins-ci.plugins:oic-auth
            8
          
            org.bouncycastle:bcprov-jdk15to18
            8
          
            org.yaml:snakeyaml
            8
          
            org.bouncycastle:bc-fips
            8
          
            io.jenkins.blueocean:blueocean
            8
          
            mysql:mysql-connector-java
            8
          
            org.apache.zeppelin:zeppelin
            8
          
            com.ruoyi:ruoyi
            8
          
            org.apache.ambari:ambari
            8
          
            org.apache.santuario:xmlsec
            8
          
            org.apache.hive:hive-service
            8
          
            org.apache.pdfbox:pdfbox
            8
          
            org.owasp.esapi:esapi
            7
          
            org.apache.druid:druid
            7
          
            org.apache.zookeeper:zookeeper
            7
          
            org.apache.wicket:wicket-core
            7
          
            org.apache.karaf:apache-karaf
            7
          
            io.atomix:atomix
            7
          
            org.owasp.antisamy:antisamy
            7
          
            com.hazelcast:hazelcast
            7
          
            org.jboss.resteasy:resteasy-client
            7
          
            ch.qos.logback:logback-core
            7
          
            io.jenkins.plugins:cavisson-ns-nd-integration
            7
          
            io.vertx:vertx-web
            7
          
            io.jenkins.plugins:miniorange-saml-sp
            7
          
            net.opentsdb:opentsdb
            7
          
            io.netty:netty-handler
            7
          
            io.jenkins.plugins:warnings-ng
            7
          
            rubygems-update
            7
          
            org.jenkins-ci.plugins:openshift-deployer
            7
          
            org.jenkins-ci.plugins:jobConfigHistory
            7
          
            org.apache.poi:poi
            7
          
            org.jruby:jruby-stdlib
            7
          
            org.apache.atlas:atlas-common
            7
          
            org.opencastproject:opencast-kernel
            7
          
            org.jenkins-ci.plugins:rundeck
            7
          
            org.jenkins-ci.plugins:artifactory
            7
          
            org.apache.inlong:manager-web
            7
          
            io.netty:netty-codec-http
            7
          
            org.keycloak:keycloak-quarkus-server
            7
          
            org.jeecgframework.boot:jeecg-boot-base
            7
          
            org.apache.derby:derby
            7
          
            io.dataease:dataease-plugin-common
            7
          
            org.apache.activemq:activemq-parent
            7
          
            org.jenkins-ci.plugins:ghprb
            6
          
            org.geoserver:gs-wms
            6
          
            org.infinispan:infinispan-core
            6
          
            org.jenkins-ci.plugins:repository-connector
            6
          
            org.jenkins-ci.plugins:htmlpublisher
            6
          
            com.nimbusds:nimbus-jose-jwt
            6
          
            org.igniterealtime.openfire:xmppserver
            6
          
            org.apache.ignite:ignite-core
            6
          
            de.tum.in.ase:artemis-java-test-sandbox
            6
          
            org.opencastproject:opencast-common
            6
          
            commons-fileupload:commons-fileupload
            6
          
            com.liferay.portal:com.liferay.portal.kernel
            6
          
            com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
            6
          
            org.jenkins-ci.plugins:ec2-deployment-dashboard
            6
          
            org.apache.struts:struts2-rest-plugin
            6
          
            org.xwiki.commons:xwiki-commons-xml
            6
          
            org.apache.syncope:syncope-core
            6
          
            org.apache.httpcomponents:httpclient
            6
          
            org.silverpeas.core:silverpeas-core
            6
          
            org.apache.shenyu:shenyu-common
            6
          
            org.wildfly:wildfly-parent
            6
          
            org.apache.axis:axis
            6
          
            org.bouncycastle:bcprov-jdk18on
            6
          
            org.apache.storm:storm-core
            6
          
            org.apache.kylin:kylin-core-common
            6
          
            org.jenkins-ci.plugins:credentials-binding
            6
          
            jquery-ui
            6
          
            org.apache.kafka:kafka
            6
          
            org.jenkins-ci.plugins:gitlab-plugin
            6
          
            org.jenkins-ci.plugins:azure-vm-agents
            6
          
            org.apache.zeppelin:zeppelin-server
            6
          
            org.jenkins-ci.plugins:fortify-on-demand-uploader
            6
          
            com.jflyfox:jflyfox_jfinal
            6
          
            org.apache.tika:tika
            6
          
            org.jeecgframework.boot:jeecg-boot-base-core
            6
          
            org.apache.pulsar:pulsar-broker
            6
          
            org.apache.mesos:mesos
            6
          
            org.webjars.npm:jquery-ui
            6
          
            tech.powerjob:powerjob
            6
          
            com.xebialabs.deployit.ci:deployit-plugin
            6
          
            hudson.plugins:project-inheritance
            6
          
            cn.hutool:hutool-json
            6
          
            org.jenkins-ci.plugins:mercurial
            6
          
            org.jenkins-ci.plugins:pipeline-maven
            6
          
            com.xuxueli:xxl-job-core
            6
          
            org.csanchez.jenkins.plugins:kubernetes
            6
          
            org.jenkins-ci.plugins:gitlab-oauth
            6
          
            org.apache.kylin:kylin-server-base
            5
          
            org.springframework.security.oauth:spring-security-oauth2
            5
          
            org.apache.hadoop:hadoop-client
            5
          
            org.jenkins-ci.plugins:support-core
            5
          
            jQuery.UI.Combined
            5
          
            org.jenkins-ci.plugins.m2release:m2release
            5
          
            org.springframework.amqp:spring-amqp
            5
          
            com.google.protobuf:protobuf-java
            5
          
            org.xwiki.platform:xwiki-platform-distribution-war
            5
          
            org.jenkins-ci.plugins:mailer
            5
          
            org.jenkins-ci.plugins:openid
            5
          
            com.datapipe.jenkins.plugins:hashicorp-vault-plugin
            5
      
      Filter by Repository
          
            https://github.com/xwiki/xwiki-platform
            222
          
          
            https://github.com/jenkinsci/jenkins
            178
          
          
            https://github.com/liferay/liferay-portal
            169
          
          
            https://github.com/apache/tomcat
            118
          
          
            https://github.com/keycloak/keycloak
            89
          
          
            https://github.com/FasterXML/jackson-databind
            70
          
          
            https://github.com/spring-projects/spring-framework
            51
          
          
            https://github.com/apache/struts
            47
          
          
            https://github.com/x-stream/xstream
            37
          
          
            https://github.com/apache/activemq
            34
          
          
            https://github.com/apache/inlong
            31
          
          
            https://github.com/CVEProject/cvelist
            28
          
          
            https://github.com/netty/netty
            27
          
          
            https://github.com/apache/nifi
            26
          
          
            https://github.com/geoserver/geoserver
            26
          
          
            https://github.com/bcgit/bc-java
            25
          
          
            https://github.com/apache/cxf
            24
          
          
            https://github.com/eclipse/jetty.project
            23
          
          
            https://github.com/jenkinsci/script-security-plugin
            22
          
          
            https://github.com/undertow-io/undertow
            21
          
          
            https://github.com/OpenNMS/opennms
            20
          
          
            https://github.com/opencast/opencast
            20
          
          
            https://github.com/jeecgboot/jeecg-boot
            20
          
          
            https://github.com/alkacon/opencms-core
            19
          
          
            https://github.com/cloudfoundry/uaa
            19
          
          
            https://github.com/apache/camel
            18
          
          
            https://github.com/vaadin/platform
            18
          
          
            https://github.com/apache/kylin
            17
          
          
            https://github.com/quarkusio/quarkus
            16
          
          
            https://github.com/xuxueli/xxl-job
            15
          
          
            https://github.com/spring-projects/spring-security
            15
          
          
            https://github.com/ming-soft/MCMS
            14
          
          
            https://github.com/Graylog2/graylog2-server
            14
          
          
            https://github.com/apache/zeppelin
            14
          
          
            https://github.com/dromara/hutool
            13
          
          
            https://github.com/apache/dolphinscheduler
            13
          
          
            https://github.com/OpenRefine/OpenRefine
            13
          
          
            https://github.com/igniterealtime/Openfire
            12
          
          
            https://github.com/DSpace/DSpace
            12
          
          
            https://github.com/h2oai/h2o-3
            12
          
          
            https://github.com/vaadin/flow
            11
          
          
            https://github.com/jenkinsci/git-plugin
            10
          
          
            https://github.com/opensearch-project/security
            10
          
          
            https://github.com/cui2shark/cms
            9
          
          
            https://github.com/apache/lucene-solr
            9
          
          
            https://github.com/dataease/dataease
            9
          
          
            https://github.com/vaadin/framework
            8
          
          
            https://github.com/jetty/jetty.project
            8
          
          
            https://github.com/vert-x3/vertx-web
            8
          
          
            https://github.com/apache/hadoop
            8
          
          
            https://github.com/apache/xmlgraphics-batik
            8
          
          
            https://github.com/pgjdbc/pgjdbc
            8
          
          
            https://github.com/nahsra/antisamy
            8
          
          
            https://github.com/jenkinsci/config-file-provider-plugin
            8
          
          
            https://github.com/xwiki/xwiki-commons
            8
          
          
            https://github.com/hazelcast/hazelcast
            8
          
          
            https://github.com/infinispan/infinispan
            7
          
          
            https://github.com/apache/openmeetings
            7
          
          
            https://github.com/OpenTSDB/opentsdb
            7
          
          
            https://github.com/jenkinsci/blueocean-plugin
            7
          
          
            https://github.com/RhinoSecurityLabs/CVEs
            7
          
          
            https://github.com/apache/syncope
            7
          
          
            https://github.com/elastic/elasticsearch
            7
          
          
            https://github.com/ratpack/ratpack
            7
          
          
            https://github.com/apache/pulsar
            7
          
          
            https://github.com/jenkinsci/build-failure-analyzer-plugin
            7
          
          
            https://github.com/apache/tika
            7
          
          
            https://github.com/rubygems/rubygems
            7
          
          
            https://github.com/rundeck/rundeck
            7
          
          
            https://github.com/http4s/http4s
            7
          
          
            https://github.com/jflyfox/jfinal_cms
            7
          
          
            https://github.com/jenkinsci/subversion-plugin
            6
          
          
            https://github.com/apache/solr
            6
          
          
            https://github.com/jenkinsci/electricflow-plugin
            6
          
          
            https://github.com/jenkinsci/fortify-on-demand-uploader-plugin
            6
          
          
            https://github.com/apache/geode
            6
          
          
            https://github.com/line/armeria
            6
          
          
            https://github.com/jenkinsci/gerrit-trigger-plugin
            6
          
          
            https://github.com/DrunkenShells/Disclosures
            6
          
          
            https://github.com/OpenAPITools/openapi-generator
            6
          
          
            https://github.com/cui2shark/security
            6
          
          
            https://github.com/JLLeitschuh/security-research
            6
          
          
            https://bitbucket.org/snakeyaml/snakeyaml
            6
          
          
            https://github.com/ESAPI/esapi-java-legacy
            6
          
          
            https://github.com/jenkinsci/ec2-plugin
            6
          
          
            https://github.com/ls1intum/Ares
            6
          
          
            https://github.com/qos-ch/logback
            6
          
          
            https://github.com/resteasy/resteasy
            6
          
          
            https://github.com/PowerJob/PowerJob
            6
          
          
            https://github.com/playframework/playframework
            6
          
          
            https://github.com/apache/hive
            6
          
          
            https://github.com/jenkinsci/configuration-as-code-plugin
            6
          
          
            https://github.com/grails/grails-core
            5
          
          
            https://github.com/jenkinsci/junit-plugin
            5
          
          
            https://github.com/jquery/jquery-ui
            5
          
          
            https://github.com/jenkinsci/gitlab-plugin
            5
          
          
            https://github.com/protocolbuffers/protobuf
            5
          
          
            https://github.com/xwiki/xwiki-rendering
            5
          
          
            https://github.com/jenkinsci/support-core-plugin
            5
          
          
            https://github.com/apache/shenyu
            5
          
          
            https://github.com/jenkinsci/active-directory-plugin
            5
          
          
            https://github.com/apache/activemq-artemis
            5
          
          
            https://github.com/h2database/h2database
            5
          
          
            https://github.com/jenkinsci/publish-over-ssh-plugin
            5
          
          
            https://github.com/jenkinsci/m2release-plugin
            5
          
          
            https://github.com/jenkinsci/codedx-plugin
            5
          
          
            https://github.com/alibaba/nacos
            5
          
          
            https://github.com/jettison-json/jettison
            5
          
          
            https://github.com/jenkinsci/email-ext-plugin
            5
          
          
            https://github.com/jenkinsci/github-plugin
            5
          
          
            https://github.com/apache/karaf
            5
          
          
            https://github.com/restlet/restlet-framework-java
            5
          
          
            https://github.com/jensdietrich/xshady-release
            5
          
          
            https://github.com/jquery/jquery
            5
          
          
            https://bitbucket.org/connect2id/nimbus-jose-jwt
            5
          
          
            https://github.com/apache/shiro
            5
          
          
            https://github.com/jenkinsci/workflow-cps-global-lib-plugin
            5
          
          
            https://github.com/apache/james-project
            5
          
          
            https://github.com/apache/httpcomponents-client
            5
          
          
            https://github.com/ktorio/ktor
            5
          
          
            https://github.com/apache/jackrabbit
            5
          
          
            https://github.com/neo4j-contrib/neo4j-apoc-procedures
            5
          
          
            https://github.com/apache/druid
            5
          
          
            https://github.com/snowflakedb/snowflake-jdbc
            5
          
          
            https://github.com/bcgit/bc-csharp
            4
          
          
            https://github.com/jenkinsci/vmanager-plugin
            4
          
          
            https://github.com/jenkinsci/xldeploy-plugin
            4
          
          
            https://github.com/apache/ranger
            4
          
          
            https://github.com/nightcloudos/new_cms
            4
          
          
            https://github.com/pippo-java/pippo
            4
          
          
            https://github.com/resteasy/Resteasy
            4
          
          
            https://github.com/joniles/mpxj
            4
          
          
            https://github.com/jenkinsci/hpe-application-automation-tools-plugin
            4
          
          
            https://github.com/xerial/snappy-java
            4
          
          
            https://github.com/apiman/apiman
            4
          
          
            https://github.com/jenkinsci/fortify-plugin
            4
          
          
            https://github.com/jfinal/jfinal
            4
          
          
            https://github.com/yamcs/yamcs
            4
          
          
            https://github.com/jenkinsci/libvirt-slave-plugin
            4
          
          
            https://github.com/HL7/fhir-ig-publisher
            4
          
          
            https://github.com/jenkinsci/matrix-project-plugin
            4
          
          
            https://github.com/powsybl/powsybl-core
            4
          
          
            https://github.com/shopizer-ecommerce/shopizer
            4
          
          
            https://github.com/wildfly/wildfly-core
            4
          
          
            https://github.com/jenkinsci/gitlab-oauth-plugin
            4
          
          
            https://github.com/AsyncHttpClient/async-http-client
            4
          
          
            https://github.com/jenkinsci/credentials-binding-plugin
            4
          
          
            https://github.com/unclebob/fitnesse
            4
          
          
            https://github.com/jenkinsci/warnings-ng-plugin
            4
          
          
            https://github.com/HtmlUnit/htmlunit
            4
          
          
            https://github.com/jenkinsci/active-choices-plugin
            4
          
          
            https://github.com/itext/itext7
            4
          
          
            https://github.com/jenkinsci/git-client-plugin
            4
          
          
            https://github.com/reportportal/reportportal
            4
          
          
            https://github.com/geonetwork/core-geonetwork
            4
          
          
            https://github.com/jenkinsci/cloudbees-jenkins-advisor-plugin
            4
          
          
            https://github.com/jenkinsci/workflow-cps-plugin
            4
          
          
            https://github.com/aws/aws-iot-device-sdk-java-v2
            4
          
          
            https://github.com/open-metadata/OpenMetadata
            4
          
          
            https://github.com/skylot/jadx
            4
          
          
            https://github.com/Robothy/local-s3
            4
          
          
            https://github.com/jenkinsci/ansible-plugin
            4
          
          
            https://github.com/jenkinsci/job-config-history-plugin
            4
          
          
            https://github.com/openhab/openhab-webui
            4
          
          
            https://github.com/apache/iotdb
            4
          
          
            https://github.com/jenkinsci/rundeck-plugin
            4
          
          
            https://github.com/wso2/carbon-identity-framework
            4
          
          
            https://github.com/jenkinsci/htmlpublisher-plugin
            4
          
          
            https://github.com/jenkinsci/p4-plugin
            4
          
          
            https://github.com/micronaut-projects/micronaut-core
            4
          
          
            https://github.com/jooby-project/jooby
            4
          
          
            https://github.com/jenkinsci/nexus-platform-plugin
            4
          
          
            https://github.com/stanfordnlp/corenlp
            4
          
          
            https://github.com/apache/zookeeper
            3
          
          
            https://github.com/hibernate/hibernate-validator
            3
          
          
            https://github.com/akka/akka-http
            3
          
          
            https://github.com/jenkinsci/cas-plugin
            3
          
          
            https://svn.apache.org/viewvc/tomcat/tc7.0.x
            3
          
          
            https://bitbucket.org/b_c/jose4j
            3
          
          
            https://github.com/apache/incubator-hugegraph
            3
          
          
            https://github.com/apache/cxf-fediz
            3
          
          
            https://github.com/matrix-org/matrix-android-sdk2
            3
          
          
            https://github.com/aws/amazon-redshift-jdbc-driver
            3
          
          
            https://github.com/jenkinsci/gitlab-branch-source-plugin
            3
          
          
            https://github.com/mbechler/marshalsec
            3
          
          
            https://github.com/reactor/reactor-netty
            3
          
          
            https://github.com/vaadin/flow-components
            3
          
          
            https://github.com/pf4j/pf4j
            3
          
          
            https://github.com/Sidd545-cr/CVE
            3
          
          
            https://github.com/jenkinsci/code-coverage-api-plugin
            3
          
          
            https://github.com/apache/flume
            3
          
          
            https://github.com/apache/dubbo
            3
          
          
            https://github.com/wso2/carbon-registry
            3
          
          
            https://github.com/google/guava
            3
          
          
            https://github.com/codehaus-plexus/plexus-utils
            3
          
          
            https://github.com/apache/commons-configuration
            3
          
          
            https://github.com/jenkinsci/crx-content-package-deployer-plugin
            3
          
          
            https://github.com/apache/rocketmq
            3
          
          
            https://github.com/jenkinsci/audit-trail-plugin
            3