{"schema_version":1,"title":"Maven package vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5,001 vulnerabilities in Maven packages: 5 in the last 7 days and 144 in the last 90 days, 102 of them critical and 21 exploited in the wild. The most recent, CVE-2026-61814, was published on 23 September 2026. 41 packages have a page of their own.","url":"https://junglewise.ai/threats/vendors/maven","json_url":"https://junglewise.ai/threats/vendors/maven.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/maven","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":181,"all_time":5001,"critical":102,"exploited":21,"last_7_days":5,"last_30_days":52,"last_90_days":144,"last_365_days":668},"latest":[{"cve":"CVE-2026-61814","cvss":7.5,"epss":0.0057,"slug":"cve-2026-61814-typelevel-jawn-asyncparser-quadratic-parsing-effort-denial-of","title":"Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered acro","severity":"high","exploited":false,"published_at":"2026-09-23T19:17:32.97+00:00","url":"https://junglewise.ai/threats/cve-2026-61814-typelevel-jawn-asyncparser-quadratic-parsing-effort-denial-of"},{"cve":"CVE-2026-59990","cvss":7.5,"epss":0.0062,"slug":"cve-2026-59990-jawn-json-parser-denial-of-service-via-uncontrolled-nesting-depth","title":"Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth","severity":"high","exploited":false,"published_at":"2026-09-23T19:17:32.637+00:00","url":"https://junglewise.ai/threats/cve-2026-59990-jawn-json-parser-denial-of-service-via-uncontrolled-nesting-depth"},{"cve":"CVE-2026-85724","cvss":9.6,"epss":0.0026,"slug":"cve-2026-85724-moquette-mqtt-broker-pattern-acl-wildcard-injection-and","title":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOpera","severity":"critical","exploited":false,"published_at":"2026-09-23T17:17:17.623+00:00","url":"https://junglewise.ai/threats/cve-2026-85724-moquette-mqtt-broker-pattern-acl-wildcard-injection-and"},{"cve":"CVE-2026-65829","cvss":5.3,"epss":0.0034,"slug":"cve-2026-65829-mpxj-path-traversal-in-primavera-p3-prx-and-suretrak-stx-readers","title":"MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, readin","severity":"medium","exploited":false,"published_at":"2026-09-22T20:17:05.06+00:00","url":"https://junglewise.ai/threats/cve-2026-65829-mpxj-path-traversal-in-primavera-p3-prx-and-suretrak-stx-readers"},{"cve":"CVE-2026-61570","cvss":7.5,"epss":0.0035,"slug":"cve-2026-61570-mpxj-xxe-vulnerability-in-merlinreader","title":"MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, Merlin","severity":"high","exploited":false,"published_at":"2026-09-22T20:17:04.287+00:00","url":"https://junglewise.ai/threats/cve-2026-61570-mpxj-xxe-vulnerability-in-merlinreader"},{"cve":"CVE-2026-85058","cvss":7.5,"epss":0.0045,"slug":"cve-2026-85058-moquette-mqtt-broker-authorization-bypass-in-will-message","title":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through","severity":"high","exploited":false,"published_at":"2026-09-18T18:17:17.447+00:00","url":"https://junglewise.ai/threats/cve-2026-85058-moquette-mqtt-broker-authorization-bypass-in-will-message"},{"cve":"CVE-2025-53837","cvss":9.9,"epss":0.0064,"slug":"cve-2025-53837-xwiki-xwiki-rendering-xml-eval-injection-via-html-macro-escaping","title":"XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XH","severity":"critical","exploited":false,"published_at":"2026-09-18T16:17:03.527+00:00","url":"https://junglewise.ai/threats/cve-2025-53837-xwiki-xwiki-rendering-xml-eval-injection-via-html-macro-escaping"},{"cve":"CVE-2026-54617","cvss":9.8,"epss":0.0068,"slug":"cve-2026-54617-gravitlauncher-launchserver-path-traversal-in-fileserverhandler","title":"GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw","severity":"critical","exploited":false,"published_at":"2026-09-17T19:16:51.003+00:00","url":"https://junglewise.ai/threats/cve-2026-54617-gravitlauncher-launchserver-path-traversal-in-fileserverhandler"},{"cve":"CVE-2026-85716","cvss":3.7,"epss":0.0041,"slug":"cve-2026-85716-asynchttpclient-scram-and-digest-mutual-authentication","title":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3","severity":"low","exploited":false,"published_at":"2026-09-17T17:16:50.943+00:00","url":"https://junglewise.ai/threats/cve-2026-85716-asynchttpclient-scram-and-digest-mutual-authentication"},{"cve":"CVE-2026-86071","cvss":3.7,"epss":0.0036,"slug":"cve-2026-86071-junrar-localfolderextractor-path-traversal-via-intermediate","title":"Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFold","severity":"low","exploited":false,"published_at":"2026-09-16T19:17:58.623+00:00","url":"https://junglewise.ai/threats/cve-2026-86071-junrar-localfolderextractor-path-traversal-via-intermediate"},{"cve":"CVE-2026-81876","cvss":7.5,"epss":0.0063,"slug":"cve-2026-81876-hapi-fhir-shcparser-deflate-infinite-loop-denial-of-service","title":"HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser","severity":"high","exploited":false,"published_at":"2026-09-16T19:17:44.45+00:00","url":"https://junglewise.ai/threats/cve-2026-81876-hapi-fhir-shcparser-deflate-infinite-loop-denial-of-service"},{"cve":"CVE-2026-81875","cvss":7.5,"epss":0.0063,"slug":"cve-2026-81875-hapi-fhir-shcparser-unbounded-deflate-decompression-denial-of","title":"HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser","severity":"high","exploited":false,"published_at":"2026-09-16T19:17:44.25+00:00","url":"https://junglewise.ai/threats/cve-2026-81875-hapi-fhir-shcparser-unbounded-deflate-decompression-denial-of"},{"cve":"CVE-2026-75516","cvss":4,"epss":0.0055,"slug":"cve-2026-75516-rabbitmq-java-client-frame-level-oom-via-math-min-with-unlimited","title":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQ","severity":"high","exploited":false,"published_at":"2026-09-16T19:17:33.56+00:00","url":"https://junglewise.ai/threats/cve-2026-75516-rabbitmq-java-client-frame-level-oom-via-math-min-with-unlimited"},{"cve":"CVE-2026-55226","cvss":5.4,"epss":0.0025,"slug":"cve-2026-55226-strimzi-kafka-operator-least-privilege-violation-in-entity","title":"Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and","severity":"medium","exploited":false,"published_at":"2026-09-15T18:17:23.807+00:00","url":"https://junglewise.ai/threats/cve-2026-55226-strimzi-kafka-operator-least-privilege-violation-in-entity"},{"cve":"CVE-2026-55225","cvss":8,"epss":0.003,"slug":"cve-2026-55225-strimzi-kafka-operator-privilege-escalation-in-kafka-spec","title":"Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:23.667+00:00","url":"https://junglewise.ai/threats/cve-2026-55225-strimzi-kafka-operator-privilege-escalation-in-kafka-spec"},{"cve":"CVE-2026-54251","cvss":4,"epss":0.0051,"slug":"cve-2026-54251-netty-netty-incubator-codec-ohttp-memory-leak-in-aead-decryption","title":"netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:22.78+00:00","url":"https://junglewise.ai/threats/cve-2026-54251-netty-netty-incubator-codec-ohttp-memory-leak-in-aead-decryption"},{"cve":"CVE-2026-65831","cvss":7.7,"epss":0.006,"slug":"cve-2026-65831-arcadedb-privilege-escalation-in-polyglot-scripting-engine","title":"ArcadeDB privilege escalation in polyglot scripting engine","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:22.387+00:00","url":"https://junglewise.ai/threats/cve-2026-65831-arcadedb-privilege-escalation-in-polyglot-scripting-engine"},{"cve":"CVE-2026-54077","cvss":7.1,"epss":0.0045,"slug":"cve-2026-54077-arcadedb-ssrf-and-local-file-read-in-import-database-statement","title":"ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportD","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:13.71+00:00","url":"https://junglewise.ai/threats/cve-2026-54077-arcadedb-ssrf-and-local-file-read-in-import-database-statement"},{"cve":"CVE-2026-54076","cvss":8.1,"epss":0.005,"slug":"cve-2026-54076-arcadedata-arcadedb-incorrect-authorization-in-engine-schema","title":"ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for added an UPDATE_SCHEMA authorization check only to LocalDocument","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:13.56+00:00","url":"https://junglewise.ai/threats/cve-2026-54076-arcadedata-arcadedb-incorrect-authorization-in-engine-schema"},{"cve":"CVE-2026-46495","cvss":4,"epss":0.0113,"slug":"cve-2026-46495-openidentityplatform-opendj-deserialization-rce-in-jmx-rmi","title":"OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/serv","severity":"critical","exploited":false,"published_at":"2026-09-15T15:17:15.493+00:00","url":"https://junglewise.ai/threats/cve-2026-46495-openidentityplatform-opendj-deserialization-rce-in-jmx-rmi"},{"cve":"CVE-2026-62379","cvss":9.8,"epss":0.0107,"slug":"cve-2026-62379-open-identity-platform-openam-rce-in-authxmlutils","title":"Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts","severity":"critical","exploited":false,"published_at":"2026-09-15T10:17:06.107+00:00","url":"https://junglewise.ai/threats/cve-2026-62379-open-identity-platform-openam-rce-in-authxmlutils"},{"cve":"CVE-2026-62280","cvss":6.1,"epss":0.0033,"slug":"cve-2026-62280-open-identity-platform-openam-reflected-xss-in-oauth2-consent","title":"Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap cons","severity":"medium","exploited":false,"published_at":"2026-09-15T10:17:05.957+00:00","url":"https://junglewise.ai/threats/cve-2026-62280-open-identity-platform-openam-reflected-xss-in-oauth2-consent"},{"cve":"CVE-2026-62263","cvss":4,"epss":0.0086,"slug":"cve-2026-62263-openidentityplatform-openam-java-deserialization-rce-in-webauthn","title":"Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInput","severity":"critical","exploited":false,"published_at":"2026-09-15T10:17:05.81+00:00","url":"https://junglewise.ai/threats/cve-2026-62263-openidentityplatform-openam-java-deserialization-rce-in-webauthn"},{"cve":"CVE-2026-53660","cvss":4,"epss":0.0041,"slug":"cve-2026-53660-openam-insecure-sso-cookie-initialization","title":"Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirector","severity":"high","exploited":false,"published_at":"2026-09-15T10:17:05.527+00:00","url":"https://junglewise.ai/threats/cve-2026-53660-openam-insecure-sso-cookie-initialization"},{"cve":"CVE-2026-48717","cvss":4,"epss":0.0053,"slug":"cve-2026-48717-open-identity-platform-openam-oauth-authorization-bypass-in-pkce","title":"Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifie","severity":"medium","exploited":false,"published_at":"2026-09-15T10:17:05.377+00:00","url":"https://junglewise.ai/threats/cve-2026-48717-open-identity-platform-openam-oauth-authorization-bypass-in-pkce"}],"vendor":{"hub":true,"name":"Maven","slug":"maven","homepage":"https://maven.apache.org/","ecosystem":"Maven","description":"A build automation and project management tool primarily used for Java projects.","url":"https://junglewise.ai/threats/vendors/maven"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-07-06","critical":2,"exploited":0,"vulnerabilities":24},{"week":"2026-07-13","critical":3,"exploited":0,"vulnerabilities":15},{"week":"2026-07-20","critical":3,"exploited":0,"vulnerabilities":9},{"week":"2026-07-27","critical":2,"exploited":0,"vulnerabilities":9},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":15},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-09-14","critical":8,"exploited":0,"vulnerabilities":37},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":5}],"most_severe":[{"cve":"CVE-2012-0391","cvss":9.8,"epss":0.756,"slug":"cve-2012-0391-apache-struts-2-improper-input-validation-vulnerability","title":"Apache Struts Remote Java Code Execution","severity":"critical","exploited":true,"published_at":"2022-05-04T00:29:43+00:00","url":"https://junglewise.ai/threats/cve-2012-0391-apache-struts-2-improper-input-validation-vulnerability"},{"cve":"CVE-2013-2251","cvss":3.1,"epss":1,"slug":"cve-2013-2251-apache-struts-improper-input-validation-vulnerability","title":"Code injection in Apache Struts","severity":"critical","exploited":true,"published_at":"2022-05-13T01:14:26+00:00","url":"https://junglewise.ai/threats/cve-2013-2251-apache-struts-improper-input-validation-vulnerability"},{"cve":"CVE-2022-24816","cvss":3.1,"epss":0.9991,"slug":"cve-2022-24816-osgeo-geoserver-jai-ext-code-injection-vulnerability","title":"Improper Control of Generation of Code ('Code Injection') in jai-ext","severity":"critical","exploited":true,"published_at":"2023-09-19T20:35:16+00:00","url":"https://junglewise.ai/threats/cve-2022-24816-osgeo-geoserver-jai-ext-code-injection-vulnerability"},{"cve":"CVE-2020-7961","cvss":3.1,"epss":0.9991,"slug":"cve-2020-7961-liferay-portal-deserialization-of-untrusted-data-vulnerability","title":"Deserialization of Untrusted Data in Liferay Portal","severity":"critical","exploited":true,"published_at":"2022-05-24T17:12:05+00:00","url":"https://junglewise.ai/threats/cve-2020-7961-liferay-portal-deserialization-of-untrusted-data-vulnerability"},{"cve":"CVE-2024-27348","cvss":3.1,"epss":0.9921,"slug":"cve-2024-27348-apache-hugegraph-server-improper-access-control-vulnerability","title":"Apache HugeGraph-Server: Command execution in gremlin","severity":"critical","exploited":true,"published_at":"2024-04-22T15:30:41+00:00","url":"https://junglewise.ai/threats/cve-2024-27348-apache-hugegraph-server-improper-access-control-vulnerability"},{"cve":"CVE-2020-10199","cvss":3.1,"epss":0.9906,"slug":"cve-2020-10199-sonatype-nexus-repository-remote-code-execution-vulnerability","title":"Nexus Repository Manager 3 - Remote Code Execution","severity":"critical","exploited":true,"published_at":"2020-04-14T15:27:05+00:00","url":"https://junglewise.ai/threats/cve-2020-10199-sonatype-nexus-repository-remote-code-execution-vulnerability"},{"cve":"CVE-2017-9791","cvss":3.1,"epss":0.9891,"slug":"cve-2017-9791-apache-struts-1-improper-input-validation-vulnerability","title":"Code execution in Apache Struts 1 plugin","severity":"critical","exploited":true,"published_at":"2022-05-13T01:26:13+00:00","url":"https://junglewise.ai/threats/cve-2017-9791-apache-struts-1-improper-input-validation-vulnerability"},{"cve":"CVE-2021-39144","cvss":3.1,"epss":0.9812,"slug":"cve-2021-39144-xstream-remote-code-execution-vulnerability","title":"XStream is vulnerable to a Remote Command Execution attack","severity":"critical","exploited":true,"published_at":"2021-08-25T14:48:19+00:00","url":"https://junglewise.ai/threats/cve-2021-39144-xstream-remote-code-execution-vulnerability"},{"cve":"CVE-2020-17519","cvss":3.1,"epss":0.9781,"slug":"cve-2020-17519-apache-flink-improper-access-control-vulnerability","title":"Path Traversal in Apache Flink","severity":"critical","exploited":true,"published_at":"2021-01-06T20:01:34+00:00","url":"https://junglewise.ai/threats/cve-2020-17519-apache-flink-improper-access-control-vulnerability"},{"cve":"CVE-2019-1003030","cvss":3.1,"epss":0.9687,"slug":"cve-2019-1003030-jenkins-matrix-project-plugin-remote-code-execution","title":"Sandbox bypass in Jenkins Pipeline: Groovy Plugin","severity":"critical","exploited":true,"published_at":"2022-05-13T01:14:26+00:00","url":"https://junglewise.ai/threats/cve-2019-1003030-jenkins-matrix-project-plugin-remote-code-execution"}],"generated_at":"2026-09-26T16:07:00.132667+00:00","technologies":[{"name":"org.keycloak:keycloak-services (Maven)","slug":"org-keycloak-keycloak-services","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-services"},{"name":"ai.h2o:h2o-core (Maven)","slug":"ai-h2o-h2o-core","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/ai-h2o-h2o-core"},{"name":"org.webjars.npm:jquery (Maven)","slug":"org-webjars-npm-jquery","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/org-webjars-npm-jquery"},{"name":"io.openremote:openremote-manager (Maven)","slug":"io-openremote-openremote-manager","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/io-openremote-openremote-manager"},{"name":"org.webjars.npm:jquery-ui (Maven)","slug":"org-webjars-npm-jquery-ui","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/org-webjars-npm-jquery-ui"},{"name":"org.yamcs:yamcs-core (Maven)","slug":"org-yamcs-yamcs-core","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/org-yamcs-yamcs-core"},{"name":"com.rabbitmq:amqp-client (Maven)","slug":"com-rabbitmq-amqp-client","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/com-rabbitmq-amqp-client"},{"name":"org.pytorch:executorch-android (Maven)","slug":"org-pytorch-executorch-android","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/org-pytorch-executorch-android"},{"name":"org.apache.dolphinscheduler:dolphinscheduler-api (Maven)","slug":"org-apache-dolphinscheduler-dolphinscheduler-api","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/org-apache-dolphinscheduler-dolphinscheduler-api"},{"name":"org.openidentityplatform.openam:openam-oauth2 (Maven)","slug":"org-openidentityplatform-openam-openam-oauth2","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/org-openidentityplatform-openam-openam-oauth2"},{"name":"org.webjars:bootstrap (Maven)","slug":"org-webjars-bootstrap","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/org-webjars-bootstrap"},{"name":"ca.uhn.hapi.fhir:org.hl7.fhir.validation (Maven)","slug":"ca-uhn-hapi-fhir-org-hl7-fhir-validation","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/ca-uhn-hapi-fhir-org-hl7-fhir-validation"},{"name":"ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli (Maven)","slug":"ca-uhn-hapi-fhir-org-hl7-fhir-validation-cli","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/ca-uhn-hapi-fhir-org-hl7-fhir-validation-cli"},{"name":"com.arcadedb:arcadedb-engine (Maven)","slug":"com-arcadedb-arcadedb-engine","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/com-arcadedb-arcadedb-engine"},{"name":"com.ctrip.framework.apollo:apollo (Maven)","slug":"com-ctrip-framework-apollo-apollo","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/com-ctrip-framework-apollo-apollo"},{"name":"io.netty.incubator:netty-incubator-codec-bhttp (Maven)","slug":"io-netty-incubator-netty-incubator-codec-bhttp","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/io-netty-incubator-netty-incubator-codec-bhttp"},{"name":"io.netty:netty-codec-http3 (Maven)","slug":"io-netty-netty-codec-http3","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/io-netty-netty-codec-http3"},{"name":"net.sf.mpxj:mpxj (Maven)","slug":"net-sf-mpxj-mpxj","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/net-sf-mpxj-mpxj"},{"name":"org.opencms:opencms-core (Maven)","slug":"org-opencms-opencms-core","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/org-opencms-opencms-core"},{"name":"org.openidentityplatform.openam:openam-core (Maven)","slug":"org-openidentityplatform-openam-openam-core","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/org-openidentityplatform-openam-openam-core"},{"name":"software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk (Maven)","slug":"software-amazon-awssdk-iotdevicesdk-aws-iot-device-sdk","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/software-amazon-awssdk-iotdevicesdk-aws-iot-device-sdk"},{"name":"ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven)","slug":"ca-uhn-hapi-fhir-org-hl7-fhir-r5","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ca-uhn-hapi-fhir-org-hl7-fhir-r5"},{"name":"com.arcadedb:arcadedb-server (Maven)","slug":"com-arcadedb-arcadedb-server","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/com-arcadedb-arcadedb-server"},{"name":"com.oviva.telematik:epa4all-client (Maven)","slug":"com-oviva-telematik-epa4all-client","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/com-oviva-telematik-epa4all-client"},{"name":"io.jenkins.plugins:pipeline-groovy-lib (Maven)","slug":"io-jenkins-plugins-pipeline-groovy-lib","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/io-jenkins-plugins-pipeline-groovy-lib"},{"name":"io.netty.incubator:netty-incubator-codec-ohttp (Maven)","slug":"io-netty-incubator-netty-incubator-codec-ohttp","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/io-netty-incubator-netty-incubator-codec-ohttp"},{"name":"io.opentelemetry.javaagent:opentelemetry-javaagent (Maven)","slug":"io-opentelemetry-javaagent-opentelemetry-javaagent","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/io-opentelemetry-javaagent-opentelemetry-javaagent"},{"name":"io.undertow:undertow-parent (Maven)","slug":"io-undertow-undertow-parent","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/io-undertow-undertow-parent"},{"name":"org.apache.openmeetings:openmeetings-parent (Maven)","slug":"org-apache-openmeetings-openmeetings-parent","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-apache-openmeetings-openmeetings-parent"},{"name":"org.apache.streampipes:streampipes-parent (Maven)","slug":"org-apache-streampipes-streampipes-parent","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-apache-streampipes-streampipes-parent"},{"name":"org.bouncycastle:bcprov-jdk14 (Maven)","slug":"org-bouncycastle-bcprov-jdk14","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-bouncycastle-bcprov-jdk14"},{"name":"org.bouncycastle:bcprov-jdk15to18 (Maven)","slug":"org-bouncycastle-bcprov-jdk15to18","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-bouncycastle-bcprov-jdk15to18"},{"name":"org.bouncycastle:bcprov-jdk18on (Maven)","slug":"org-bouncycastle-bcprov-jdk18on","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-bouncycastle-bcprov-jdk18on"},{"name":"org.jenkins-ci.plugins:active-directory (Maven)","slug":"org-jenkins-ci-plugins-active-directory","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-active-directory"},{"name":"org.jenkins-ci.plugins:assembla (Maven)","slug":"org-jenkins-ci-plugins-assembla","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-assembla"},{"name":"org.jenkins-ci.plugins:contrast-continuous-application-security (Maven)","slug":"org-jenkins-ci-plugins-contrast-continuous-application-security","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-contrast-continuous-application-security"},{"name":"org.jenkins-ci.plugins:gitee (Maven)","slug":"org-jenkins-ci-plugins-gitee","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-gitee"},{"name":"org.thymeleaf:thymeleaf (Maven)","slug":"org-thymeleaf-thymeleaf","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-thymeleaf-thymeleaf"},{"name":"org.thymeleaf:thymeleaf-spring5 (Maven)","slug":"org-thymeleaf-thymeleaf-spring5","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-thymeleaf-thymeleaf-spring5"},{"name":"org.thymeleaf:thymeleaf-spring6 (Maven)","slug":"org-thymeleaf-thymeleaf-spring6","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-thymeleaf-thymeleaf-spring6"},{"name":"org.webjars.npm:xlsx (Maven)","slug":"org-webjars-npm-xlsx","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/org-webjars-npm-xlsx"}]}