Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.account.admin.web[,2.0.108)Maven30 Oct 2025
  • M
Insertion of Sensitive Information into Log File
com.liferay:com.liferay.portal.security.ldap.impl[,4.0.54)Maven30 Oct 2025
  • M
Open Redirect
com.liferay:com.liferay.layout.admin.web[,5.0.157)Maven30 Oct 2025
  • M
Cleartext Storage of Sensitive Information
com.liferay.portal:com.liferay.portal.impl[,93.0.0)Maven30 Oct 2025
  • M
Missing Authentication for Critical Function
com.liferay.portal:com.liferay.portal.impl[,97.0.0)Maven30 Oct 2025
  • M
Session Fixation
org.keycloak:keycloak-services[,26.0.0)Maven30 Oct 2025
  • H
Command Injection
org.jenkins-ci.plugins:azure-cli[0,]Maven30 Oct 2025
  • M
Cleartext Transmission of Sensitive Information
io.jenkins.plugins:byteguard-build-actions[0,]Maven30 Oct 2025
  • M
Cleartext Transmission of Sensitive Information
com.openshift.jenkins:openshift-pipeline[0,]Maven30 Oct 2025
  • M
Cross-site Request Forgery (CSRF)
org.jenkins-ci.plugins:nexus-task-runner[0,]Maven30 Oct 2025
  • M
Missing Authorization
org.jenkins-ci.plugins:nexus-task-runner[0,]Maven30 Oct 2025
  • M
Missing Authorization
org.jenkins-ci.plugins:windocks-start-container[0,]Maven30 Oct 2025
  • H
XML External Entity (XXE) Injection
org.jenkins-ci.plugins:jdepend[0,]Maven30 Oct 2025
  • M
Cleartext Transmission of Sensitive Information
org.jenkins-ci.plugins:curseforge-publisher[0,]Maven30 Oct 2025
  • M
Cross-site Request Forgery (CSRF)
jp.ikedam.jenkins.plugins:extensible-choice-parameter[0,]Maven30 Oct 2025
  • M
Cross-site Request Forgery (CSRF)
org.jenkins-ci.plugins:windocks-start-container[0,]Maven30 Oct 2025
  • H
Insecure Default Initialization of Resource
io.jenkins.plugins:eggplant-runner[0,]Maven30 Oct 2025
  • M
Cleartext Transmission of Sensitive Information
io.jenkins.plugins:byteguard-build-actions[0,]Maven30 Oct 2025
  • M
Cleartext Transmission of Sensitive Information
org.jenkins-ci.plugins:curseforge-publisher[0,]Maven30 Oct 2025
  • M
Missing Authorization
io.jenkins.plugins:mcp-server[,0.86.v7d3355e6a_a_18)Maven30 Oct 2025
  • M
Missing Authorization
org.jenkins-ci.plugins:themis[0,]Maven30 Oct 2025
  • M
Cross-site Request Forgery (CSRF)
org.jenkins-ci.plugins:themis[0,]Maven30 Oct 2025
  • M
Cross-site Request Forgery (CSRF)
org.jenkins-ci.plugins:publish-to-bitbucket[0,]Maven30 Oct 2025
  • M
Missing Authorization
org.jenkins-ci.plugins:publish-to-bitbucket[0,]Maven30 Oct 2025
  • M
Missing Authorization
org.jenkins-ci.plugins:publish-to-bitbucket[0,]Maven30 Oct 2025
  • H
Replay Attack
org.jenkins-ci.plugins:saml[,4.583.585.v22ccc1139f55)Maven30 Oct 2025
  • H
Allocation of Resources Without Limits or Throttling
com.liferay:com.liferay.portal.vulcan.impl[,5.0.104)Maven30 Oct 2025
  • H
Cross-site Request Forgery (CSRF)
com.liferay:com.liferay.headless.discovery.web[0,]Maven29 Oct 2025
  • H
Untrusted Search Path
org.apache.tomcat:tomcat[9.0.23,9.0.106)[10.1.0,10.1.42)[11.0.0-M1,11.0.8)Maven29 Oct 2025
  • H
Untrusted Search Path
org.apache.tomcat:tomcat-catalina[9.0.23,9.0.106)[10.1.0,10.1.42)[11.0.0-M1,11.0.8)Maven29 Oct 2025