maven
Security Advisories in maven
High
2 days ago
io.moquette:moquette-broker has a Missing Authorization issue
maven
io.moquette:moquette-broker
Critical
2 days ago
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
maven
org.xwiki.rendering:xwiki-rendering-xml
High
2 days ago
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
npm, maven
paella-core, org.opencastproject:opencast-engage-paella-player-7
High
3 days ago
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
maven
ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli, ca.uhn.hapi.fhir:org.hl7.fhir.validation, ca.uhn.hapi.fhir:org.hl7.fhir.r5
High
3 days ago
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
maven
ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli, ca.uhn.hapi.fhir:org.hl7.fhir.validation, ca.uhn.hapi.fhir:org.hl7.fhir.r5
Moderate
3 days ago
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
maven
org.asynchttpclient:async-http-client
Moderate
3 days ago
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
maven
org.asynchttpclient:async-http-client
High
3 days ago
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
maven
org.asynchttpclient:async-http-client
Low
3 days ago
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
maven
org.asynchttpclient:async-http-client
Moderate
3 days ago
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
maven
io.kestra:kestra
High
3 days ago
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
maven
io.kestra:kestra-core, io.kestra:core
Low
3 days ago
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
maven
com.github.junrar:junrar
Low
3 days ago
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
maven
org.mariadb.jdbc:mariadb-java-client
High
3 days ago
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
maven
com.squareup.wire:wire-runtime
High
3 days ago
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
maven
com.rabbitmq:amqp-client
High
5 days ago
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
maven
org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
Moderate
5 days ago
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
maven
org.http4s:http4s-server_2.13, org.http4s:http4s-server_3, org.http4s:http4s-server_2.12
High
5 days ago
Http4s Ember HTTP/2: unbounded continuation frame accumulation
maven
org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
Moderate
5 days ago
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
maven
org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
Moderate
5 days ago
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
maven
org.http4s:http4s-client_3, org.http4s:http4s-client_2.13, org.http4s:http4s-client_2.12
Moderate
5 days ago
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
maven
org.http4s:http4s-client_3, org.http4s:http4s-client_2.13, org.http4s:http4s-client_2.12
High
5 days ago
Http4s Ember HTTP/2 has an unbounded outbound frame queue
maven
org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.12
High
5 days ago
Http4s: DigestAuth nonce map grows unbounded
maven
org.http4s:http4s-ember-server_3, org.http4s:http4s-ember-server_2.13, org.http4s:http4s-ember-server_2.12
Moderate
5 days ago
Http4s: DigestAuth allows replay of captured requests
maven
org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
High
5 days ago
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
maven
org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
Critical
5 days ago
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
maven
org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
High
5 days ago
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
maven
org.http4s:http4s-ember-core_2.12
High
5 days ago
Http4s Ember HTTP/2: unbounded inbound body buffering
maven
org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
High
9 days ago
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
maven
com.linecorp.centraldogma:centraldogma-server-mirror-git
Critical
9 days ago
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover
maven
com.linecorp.centraldogma:centraldogma-server
Moderate
9 days ago
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
maven
com.linecorp.centraldogma:centraldogma-server-auth-shiro
High
11 days ago
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
maven
org.geonetwork-opensource:gn-web-app
Critical
12 days ago
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
maven
io.netty:netty-handler
Moderate
12 days ago
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
maven
io.netty:netty-handler
High
18 days ago
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
maven
com.github.jknack:handlebars-springmvc
Moderate
23 days ago
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
maven
org.mariadb:r2dbc-mariadb
Moderate
23 days ago
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
maven
org.mariadb:r2dbc-mariadb
Moderate
23 days ago
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
maven
org.mariadb.jdbc:mariadb-java-client
Moderate
23 days ago
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
maven
org.mariadb.jdbc:mariadb-java-client
Moderate
23 days ago
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
maven
org.mariadb.jdbc:mariadb-java-client
High
23 days ago
MapFish Print has XXE that allows reading arbitrary files of certain types
maven
org.mapfish.print:print-servlet, org.mapfish.print:print-lib, org.mapfish:print.print-servlet
Moderate
23 days ago
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
maven
org.graylog2:graylog2-server
High
23 days ago
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
maven
org.graylog2:graylog2-server
High
23 days ago
PowSyBl Core has Command Injection in LocalCommandExecutor-s
maven
com.powsybl:powsybl-computation-local
High
23 days ago
Spinnaker: Improper yaml processing on kustomize bake operations
maven
io.spinnaker.rosco:rosco-manifests
Moderate
23 days ago
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
maven
org.graylog2:graylog2-server
Critical
23 days ago
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
maven
org.yamcs:yamcs-core
Critical
23 days ago
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
maven
org.yamcs:yamcs-core
Moderate
23 days ago
Yamcs has Reflected XSS in the URL of the Authorize Endpoint
maven
org.yamcs:yamcs-core
Moderate
23 days ago
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
maven
org.yamcs:yamcs-core
Moderate
23 days ago
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
maven
org.yamcs:yamcs-core
Moderate
23 days ago
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
maven
org.yamcs:yamcs-core
High
23 days ago
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
maven
org.yamcs:yamcs-core
Critical
23 days ago
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
maven
org.yamcs:yamcs-core
Moderate
25 days ago
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
maven
org.asynchttpclient:async-http-client
High
25 days ago
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
maven
org.codehaus.izpack:izpack-installer
High
25 days ago
http4s has HTTP/2 Denial of Service with Ember Backend
maven
org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.12
Critical
26 days ago
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability
maven
org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat
Critical
26 days ago
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
maven
org.apache.tomcat:tomcat-catalina, org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
Critical
26 days ago
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat
Moderate
27 days ago
Sakai Profile Image Deletion has an IDOR
maven
org.sakaiproject.profile2:profile2-impl, org.sakaiproject.profile2:profile2-api
High
27 days ago
Sakai Conversations has a Stored XSS Issue
maven
org.sakaiproject.rubrics:rubrics-impl, org.sakaiproject.kernel:sakai-kernel-impl, org.sakaiproject.conversations:sakai-conversations-impl
Critical
27 days ago
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
maven
org.apache.camel:camel-undertow
Moderate
27 days ago
Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
maven
org.apache.camel:camel-azure-storage-datalake
Moderate
27 days ago
Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
maven
org.apache.camel:camel-knative
High
27 days ago
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
maven
org.apache.camel:camel-google-storage
Critical
27 days ago
Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace
maven
org.apache.camel:camel-atmosphere-websocket
Moderate
27 days ago
Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
maven
org.apache.camel:camel-mail
Critical
27 days ago
Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
maven
org.apache.camel:camel-azure-storage-blob
High
27 days ago
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
maven
org.apache.camel:camel-platform-http-main
Critical
30 days ago
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
maven
org.geotools.jdbc:gt-jdbc-postgis
High
about 1 month ago
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
maven
io.netty.incubator:netty-incubator-codec-bhttp
High
about 1 month ago
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
maven
io.netty.incubator:netty-incubator-codec-bhttp
High
about 1 month ago
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
maven
io.netty.incubator:netty-incubator-codec-bhttp
Moderate
about 1 month ago
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
maven
io.netty.incubator:netty-incubator-codec-bhttp
High
about 1 month ago
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
maven
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
High
about 1 month ago
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
maven
io.netty.incubator:netty-incubator-codec-ohttp
High
about 1 month ago
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
maven
org.geoserver.web:gs-web-app, org.geoserver:gs-wms, org.geoserver:gs-main
High
about 1 month ago
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
maven
org.xwiki.platform:xwiki-platform-livedata-livetable
Critical
about 1 month ago
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass
maven
org.keycloak:keycloak-services
Low
about 1 month ago
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
maven
com.rabbitmq:amqp-client
Moderate
about 1 month ago
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
maven
com.rabbitmq:amqp-client
Moderate
about 1 month ago
RabbitMQ Java client malformed body frame triggers raw command assembler exception
maven
com.rabbitmq:amqp-client
High
about 1 month ago
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
maven
com.rabbitmq:amqp-client
High
about 1 month ago
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
maven
com.rabbitmq:amqp-client
High
about 1 month ago
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
maven
com.rabbitmq:amqp-client
High
about 1 month ago
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
maven
io.kestra:kestra
High
about 1 month ago
http4k: `DigestAuthProvider.verify` did not bind to request URI
maven
org.http4k:http4k-security-digest
Moderate
about 1 month ago
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
maven
org.http4k:http4k-security-digest
High
about 1 month ago
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
maven
org.docx4j:docx4j-core
High
about 1 month ago
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
maven
org.http4k:http4k-core
Moderate
about 1 month ago
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
maven
io.netty:netty-codec-http
High
about 1 month ago
Netty: Memory Exhaustion in SctpMessageCompletionHandler
maven
io.netty:netty-transport-sctp
High
about 1 month ago
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
maven
com.mchange:mchange-commons-java
High
about 1 month ago
OpenAM Insecure SSO Cookie Initialization
maven
org.openidentityplatform.openam:openam-core
Critical
about 1 month ago
Apache Ranger has a Command Injection vulnerability
maven
org.apache.ranger:ranger
High
about 1 month ago
Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound
maven
org.bouncycastle:bc-fips
High
about 1 month ago
Bouncy Castle: Zeroisation of sensitive key material on garbage collection relies on finalization.
maven
org.bouncycastle:bc-fips
Filter by Severity
Filter by Package
org.jenkins-ci.main:jenkins-core
259
org.apache.tomcat:tomcat
160
com.liferay.portal:release.portal.bom
150
com.liferay.portal:release.dxp.bom
123
org.keycloak:keycloak-services
98
com.fasterxml.jackson.core:jackson-databind
79
org.apache.struts:struts2-core
59
org.apache.tomcat.embed:tomcat-embed-core
57
org.keycloak:keycloak-core
50
org.xwiki.platform:xwiki-platform-oldcore
46
org.elasticsearch:elasticsearch
44
net.mingsoft:ms-mcms
39
io.undertow:undertow-core
39
com.thoughtworks.xstream:xstream
37
com.jfinal:jfinal
36
org.jenkins-ci.plugins:script-security
34
org.apache.tomcat:tomcat-catalina
34
org.opencms:opencms-core
31
org.springframework.security:spring-security-core
30
org.apache.solr:solr-core
30
org.eclipse.jetty:jetty-server
29
org.keycloak:keycloak-parent
26
org.apache.openmeetings:openmeetings-parent
25
org.bouncycastle:bcprov-jdk14
24
org.springframework:spring-webmvc
24
io.netty:netty-codec-http
23
org.xwiki.platform:xwiki-platform-web-templates
23
org.cloudfoundry.identity:cloudfoundry-identity-server
21
org.apache.nifi:nifi
21
org.apache.tomcat:tomcat-coyote
20
org.springframework:spring-core
19
com.vaadin:vaadin-bom
18
org.apache.jspwiki:jspwiki-main
18
org.apache.activemq:activemq-client
18
org.springframework:spring-webflux
18
org.apache.ranger:ranger
17
org.apache.dolphinscheduler:dolphinscheduler
17
org.apache.geode:geode-core
17
org.apache.inlong:manager-pojo
17
com.liferay.portal:com.liferay.portal.impl
17
org.yamcs:yamcs-core
16
org.apache.dubbo:dubbo
16
org.apache.struts.xwork:xwork-core
15
org.geoserver.web:gs-web-app
15
org.graylog2:graylog2-server
15
org.xwiki.platform:xwiki-platform-web
15
org.apache.activemq:apache-activemq
14
org.bouncycastle:bcprov-jdk15
14
org.opensearch.plugin:opensearch-security
14
ai.h2o:h2o-core
14
com.vaadin:flow-server
13
org.apache.tika:tika-core
13
org.apache.hadoop:hadoop-main
13
org.apache.cxf:cxf-core
13
org.bouncycastle:bcprov-jdk15to18
13
org.apache.kylin:kylin
13
org.springframework:spring-web
13
io.netty:netty-handler
12
org.apache.streampark:streampark
12
org.bouncycastle:bc-fips
12
org.jenkins-ci.plugins:email-ext
12
org.apache.cassandra:cassandra-all
12
org.jenkins-ci.plugins.workflow:workflow-cps
12
org.apache.hadoop:hadoop-common
12
org.apache.shiro:shiro-core
12
org.jeecgframework.boot:jeecg-boot-parent
12
org.jenkins-ci.plugins:git
12
org.apache.activemq:activemq-broker
12
com.xuxueli:xxl-job
11
org.postgresql:postgresql
11
org.apache.archiva:archiva
11
io.netty:netty
11
org.apache.commons:commons-compress
11
org.bouncycastle:bcprov-jdk18on
11
org.http4s:http4s-ember-core_2.12
11
org.xwiki.platform:xwiki-platform-rest-server
11
org.xwiki.platform:xwiki-platform-administration-ui
11
org.apache.camel:camel-core
11
org.jenkins-ci.plugins:active-directory
11
org.apache.james:james-server
11
org.apache.jspwiki:jspwiki-war
11
org.mortbay.jetty:jetty
11
h2o
11
org.igniterealtime.openfire:parent
11
io.netty:netty-codec-http2
11
org.apache.activemq:activemq-all
10
org.apache.logging.log4j:log4j-core
10
org.apache.inlong:manager-service
10
org.apache.cxf:cxf
10
ch.qos.logback:logback-core
10
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
10
org.apache.linkis:linkis
10
org.craftercms:crafter-studio
10
org.bouncycastle:bcprov-jdk15on
10
org.http4s:http4s-ember-core_2.13
10
org.http4s:http4s-ember-core_3
10
org.jboss.netty:netty
10
org.jenkins-ci.plugins.workflow:workflow-cps-global-lib
10
org.apache.hive:hive-exec
9
ca.uhn.hapi.fhir:org.hl7.fhir.validation
9
org.geoserver:gs-wms
9
cn.hutool:hutool-core
9
org.apache.zookeeper:zookeeper
9
org.asynchttpclient:async-http-client
9
tools.jackson.core:jackson-databind
9
ca.uhn.hapi.fhir:org.hl7.fhir.r5
9
org.opencrx:opencrx-core-models
9
org.keycloak:keycloak-quarkus-server
9
com.rabbitmq:amqp-client
9
org.apache.dolphinscheduler:dolphinscheduler-api
9
org.jenkins-ci.plugins:electricflow
9
org.opennms:opennms
9
io.jenkins:configuration-as-code
9
org.jenkins-ci.plugins:config-file-provider
9
org.apache.hive:hive
9
org.apache.xmlgraphics:batik
9
org.apache.tapestry:tapestry-core
9
org.apache.spark:spark-core_2.11
9
org.jenkins-ci.plugins:subversion
8
org.jenkins-ci.plugins:credentials-binding
8
org.springframework:spring-expression
8
org.yaml:snakeyaml
8
org.apache.zeppelin:zeppelin
8
org.apache.hive:hive-service
8
org.apache.spark:spark-core_2.10
8
io.jenkins.blueocean:blueocean
8
org.dspace:dspace-api
8
org.apache.ambari:ambari
8
org.apache.druid:druid
8
com.hazelcast:hazelcast
8
org.jeecgframework.boot:jeecg-boot-common
8
org.jenkins-ci.plugins:ec2
8
org.silverpeas.core:silverpeas-core-web
8
org.apache.santuario:xmlsec
8
org.springframework.cloud:spring-cloud-config-server
8
mysql:mysql-connector-java
8
org.jenkins-ci.plugins:oic-auth
8
org.apache.mina:mina-core
8
com.ruoyi:ruoyi
8
org.apache.ozone:ozone-main
8
org.apache.wicket:wicket-core
8
org.apache.pdfbox:pdfbox
8
org.infinispan:infinispan-core
7
org.apache.kafka:kafka-clients
7
jQuery.UI.Combined
7
com.xuxueli:xxl-job-admin
7
org.jruby:jruby-stdlib
7
org.silverpeas.core:silverpeas-core
7
org.webjars.npm:jquery-ui
7
io.vertx:vertx-web
7
io.jenkins.plugins:miniorange-saml-sp
7
org.apache.axis:axis
7
org.apache.activemq:activemq-parent
7
tech.powerjob:powerjob
7
org.springframework.data:spring-data-commons
7
org.owasp.esapi:esapi
7
org.apache.karaf:apache-karaf
7
org.apache.inlong:manager-web
7
com.ctrip.framework.apollo:apollo
7
io.jenkins.plugins:warnings-ng
7
org.apache.atlas:atlas-common
7
org.jenkins-ci.plugins:rundeck
7
com.vaadin:vaadin-server
7
io.openremote:openremote-manager
7
ca.uhn.hapi.fhir:org.hl7.fhir.utilities
7
org.jenkins-ci.plugins:htmlpublisher
7
net.gleske:jervis
7
org.jeecgframework.boot:jeecg-boot-base
7
org.apache.ignite:ignite-core
7
org.springframework.data:spring-data-rest-core
7
io.dataease:dataease-plugin-common
7
io.atomix:atomix
7
org.apache.syncope:syncope-core
7
org.keycloak:keycloak-server-spi-private
7
org.jenkins-ci.plugins:openshift-deployer
7
org.apache.poi:poi
7
org.jenkins-ci.plugins:artifactory
7
org.openidentityplatform.openam:openam-oauth2
7
org.opencastproject:opencast-kernel
7
io.vertx:vertx-core
7
net.opentsdb:opentsdb
7
io.jenkins.plugins:cavisson-ns-nd-integration
7
org.jboss.resteasy:resteasy-client
7
org.geoserver:gs-main
7
ca.uhn.hapi.fhir:org.hl7.fhir.r4b
7
org.owasp.antisamy:antisamy
7
org.apache.derby:derby
7
jquery-ui
7
org.springframework.amqp:spring-amqp
7
org.jenkins-ci.plugins:jobConfigHistory
7
rubygems-update
7
org.jenkins-ci.plugins:ghprb
6
com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
6
org.opencastproject:opencast-common
6
org.jenkins-ci.plugins:ec2-deployment-dashboard
6
org.apache.pulsar:pulsar-broker
6
org.jenkins-ci.plugins:mercurial
6
com.xebialabs.deployit.ci:deployit-plugin
6
org.apache.streampipes:streampipes-parent
6
org.apache.nifi:nifi-web-api
6
Filter by Repository
https://github.com/xwiki/xwiki-platform
222
https://github.com/jenkinsci/jenkins
178
https://github.com/liferay/liferay-portal
170
https://github.com/apache/tomcat
118
https://github.com/keycloak/keycloak
89
https://github.com/FasterXML/jackson-databind
70
https://github.com/spring-projects/spring-framework
51
https://github.com/apache/struts
47
https://github.com/x-stream/xstream
37
https://github.com/apache/activemq
34
https://github.com/apache/inlong
31
https://github.com/CVEProject/cvelist
28
https://github.com/netty/netty
27
https://github.com/apache/nifi
26
https://github.com/geoserver/geoserver
26
https://github.com/bcgit/bc-java
25
https://github.com/apache/cxf
24
https://github.com/eclipse/jetty.project
23
https://github.com/jenkinsci/script-security-plugin
22
https://github.com/undertow-io/undertow
21
https://github.com/jeecgboot/jeecg-boot
20
https://github.com/OpenNMS/opennms
20
https://github.com/opencast/opencast
20
https://github.com/alkacon/opencms-core
19
https://github.com/cloudfoundry/uaa
19
https://github.com/apache/camel
18
https://github.com/vaadin/platform
18
https://github.com/apache/kylin
17
https://github.com/quarkusio/quarkus
16
https://github.com/xuxueli/xxl-job
15
https://github.com/spring-projects/spring-security
15
https://github.com/Graylog2/graylog2-server
14
https://github.com/apache/zeppelin
14
https://github.com/ming-soft/MCMS
14
https://github.com/OpenRefine/OpenRefine
13
https://github.com/apache/dolphinscheduler
13
https://github.com/dromara/hutool
13
https://github.com/igniterealtime/Openfire
12
https://github.com/DSpace/DSpace
12
https://github.com/vaadin/flow
11
https://github.com/jenkinsci/git-plugin
10
https://github.com/opensearch-project/security
10
https://github.com/apache/lucene-solr
10
https://github.com/h2oai/h2o-3
10
https://github.com/dataease/dataease
9
https://github.com/cui2shark/cms
9
https://github.com/pgjdbc/pgjdbc
8
https://github.com/vaadin/framework
8
https://github.com/jetty/jetty.project
8
https://github.com/apache/xmlgraphics-batik
8
https://github.com/apache/hadoop
8
https://github.com/vert-x3/vertx-web
8
https://github.com/jenkinsci/config-file-provider-plugin
8
https://github.com/xwiki/xwiki-commons
8
https://github.com/hazelcast/hazelcast
8
https://github.com/nahsra/antisamy
8
https://github.com/RhinoSecurityLabs/CVEs
7
https://github.com/apache/pulsar
7
https://github.com/jenkinsci/blueocean-plugin
7
https://github.com/apache/openmeetings
7
https://github.com/OpenTSDB/opentsdb
7
https://github.com/infinispan/infinispan
7
https://github.com/elastic/elasticsearch
7
https://github.com/ratpack/ratpack
7
https://github.com/apache/syncope
7
https://github.com/apache/tika
7
https://github.com/jenkinsci/build-failure-analyzer-plugin
7
https://github.com/rubygems/rubygems
7
https://github.com/jflyfox/jfinal_cms
7
https://github.com/rundeck/rundeck
7
https://github.com/http4s/http4s
7
https://github.com/ESAPI/esapi-java-legacy
6
https://github.com/JLLeitschuh/security-research
6
https://github.com/apache/hive
6
https://bitbucket.org/snakeyaml/snakeyaml
6
https://github.com/jquery/jquery-ui
6
https://github.com/apache/geode
6
https://github.com/playframework/playframework
6
https://github.com/OpenAPITools/openapi-generator
6
https://github.com/jenkinsci/electricflow-plugin
6
https://github.com/apache/solr
6
https://github.com/jenkinsci/gerrit-trigger-plugin
6
https://github.com/line/armeria
6
https://github.com/jenkinsci/fortify-on-demand-uploader-plugin
6
https://github.com/jenkinsci/ec2-plugin
6
https://github.com/qos-ch/logback
6
https://github.com/cui2shark/security
6
https://github.com/PowerJob/PowerJob
6
https://github.com/jenkinsci/configuration-as-code-plugin
6
https://github.com/resteasy/resteasy
6
https://github.com/jenkinsci/subversion-plugin
6
https://github.com/DrunkenShells/Disclosures
6
https://github.com/neo4j-contrib/neo4j-apoc-procedures
5
https://github.com/jenkinsci/gitlab-plugin
5
https://github.com/jenkinsci/m2release-plugin
5
https://github.com/jensdietrich/xshady-release
5
https://github.com/apache/karaf
5
https://github.com/apache/activemq-artemis
5
https://github.com/apache/james-project
5
https://github.com/h2database/h2database
5
https://github.com/apache/druid
5
https://github.com/jenkinsci/codedx-plugin
5
https://github.com/apache/jackrabbit
5
https://github.com/apache/shiro
5
https://github.com/jenkinsci/github-plugin
5
https://github.com/protocolbuffers/protobuf
5
https://github.com/grails/grails-core
5
https://github.com/apache/shenyu
5
https://bitbucket.org/connect2id/nimbus-jose-jwt
5
https://github.com/alibaba/nacos
5
https://github.com/jenkinsci/junit-plugin
5
https://github.com/jenkinsci/email-ext-plugin
5
https://github.com/restlet/restlet-framework-java
5
https://github.com/jenkinsci/active-directory-plugin
5
https://github.com/jenkinsci/support-core-plugin
5
https://github.com/jettison-json/jettison
5
https://github.com/snowflakedb/snowflake-jdbc
5
https://github.com/apache/httpcomponents-client
5
https://github.com/xwiki/xwiki-rendering
5
https://github.com/jenkinsci/workflow-cps-global-lib-plugin
5
https://github.com/jenkinsci/publish-over-ssh-plugin
5
https://github.com/ktorio/ktor
5
https://github.com/wso2/carbon-identity-framework
4
https://github.com/joniles/mpxj
4
https://github.com/pippo-java/pippo
4
https://github.com/powsybl/powsybl-core
4
https://github.com/nightcloudos/new_cms
4
https://github.com/stanfordnlp/corenlp
4
https://github.com/jenkinsci/xldeploy-plugin
4
https://github.com/jenkinsci/vmanager-plugin
4
https://github.com/jenkinsci/warnings-ng-plugin
4
https://github.com/apache/ranger
4
https://github.com/jenkinsci/libvirt-slave-plugin
4
https://github.com/jenkinsci/htmlpublisher-plugin
4
https://github.com/skylot/jadx
4
https://github.com/open-metadata/OpenMetadata
4
https://github.com/apache/streampipes
4
https://github.com/apache/iotdb
4
https://github.com/shopizer-ecommerce/shopizer
4
https://github.com/jenkinsci/cloudbees-jenkins-advisor-plugin
4
https://github.com/jenkinsci/fortify-plugin
4
https://github.com/HL7/fhir-ig-publisher
4
https://github.com/apiman/apiman
4
https://github.com/geonetwork/core-geonetwork
4
https://github.com/xerial/snappy-java
4
https://github.com/jenkinsci/matrix-project-plugin
4
https://github.com/jenkinsci/nexus-platform-plugin
4
https://github.com/AsyncHttpClient/async-http-client
4
https://github.com/unclebob/fitnesse
4
https://github.com/jenkinsci/hpe-application-automation-tools-plugin
4
https://github.com/jfinal/jfinal
4
https://github.com/micronaut-projects/micronaut-core
4
https://github.com/wildfly/wildfly-core
4
https://github.com/resteasy/Resteasy
4
https://github.com/aws/aws-iot-device-sdk-java-v2
4
https://github.com/jenkinsci/credentials-binding-plugin
4
https://github.com/jenkinsci/workflow-cps-plugin
4
https://github.com/jenkinsci/gitlab-oauth-plugin
4
https://github.com/reportportal/reportportal
4
https://github.com/openhab/openhab-webui
4
https://github.com/jenkinsci/git-client-plugin
4
https://github.com/jooby-project/jooby
4
https://github.com/jquery/jquery
4
https://github.com/HtmlUnit/htmlunit
4
https://github.com/itext/itext7
4
https://github.com/yamcs/yamcs
4
https://github.com/jenkinsci/job-config-history-plugin
4
https://github.com/jenkinsci/ansible-plugin
4
https://github.com/jenkinsci/active-choices-plugin
4
https://github.com/Robothy/local-s3
4
https://github.com/jenkinsci/p4-plugin
4
https://github.com/jenkinsci/rundeck-plugin
4
https://github.com/graphql-java/graphql-java
3
https://github.com/bcgit/bc-csharp
3
https://bitbucket.org/b_c/jose4j
3
https://github.com/jenkinsci/embeddable-build-status-plugin
3
https://github.com/hibernate/hibernate-validator
3
https://github.com/jenkinsci/cas-plugin
3
https://github.com/ls1intum/Ares
3
https://github.com/jenkinsci/gitlab-branch-source-plugin
3
https://github.com/reactor/reactor-netty
3
https://github.com/spring-projects/spring-boot
3
https://github.com/mbechler/marshalsec
3
https://github.com/jenkinsci/azure-credentials-plugin
3
https://github.com/aws/amazon-redshift-jdbc-driver
3
https://github.com/apache/santuario-java
3
https://github.com/jenkinsci/mercurial-plugin
3
https://github.com/li-yu320/cms
3
https://github.com/wildfly/wildfly
3
https://github.com/Adobe-Consulting-Services/acs-aem-commons
3
https://github.com/matrix-org/matrix-android-sdk2
3
https://github.com/apache/cxf-fediz
3
https://github.com/HubSpot/jinjava
3
https://github.com/apache/zookeeper
3
https://github.com/jenkinsci/kubernetes-plugin
3
https://svn.apache.org/viewvc/tomcat/tc7.0.x
3
https://github.com/akka/akka-http
3
https://github.com/vaadin/flow-components
3
https://github.com/javamelody/javamelody
3