Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Timing Attack
com.liferay:com.liferay.portal.workflow.api[7.0.1,11.0.1)Maven11 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.search.web[6.0.125,6.0.143)Maven11 Sept 2025
  • M
Allocation of Resources Without Limits or Throttling
org.webjars.bower:axios[0,]Maven11 Sept 2025
  • M
Allocation of Resources Without Limits or Throttling
org.webjars.bowergithub.axios:axios[0,]Maven11 Sept 2025
  • M
Allocation of Resources Without Limits or Throttling
org.webjars.npm:axios[,1.12.2)Maven11 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.workflow.task.web[,5.0.76)Maven11 Sept 2025
  • M
Information Exposure
com.liferay:com.liferay.portal.security.sso.openid.connect.impl[0,]Maven11 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.workflow.web[0,]Maven11 Sept 2025
  • M
Server-side Request Forgery (SSRF)
com.liferay:com.liferay.object.service[,1.0.208)Maven11 Sept 2025
  • L
Cross-site Scripting (XSS)
org.webjars.bower:jsondiffpatch[0,]Maven10 Sept 2025
  • L
Cross-site Scripting (XSS)
org.webjars.npm:jsondiffpatch[0,]Maven10 Sept 2025
  • C
Expression Language Injection
org.springframework.cloud:spring-cloud-gateway-server[,4.2.5)[4.3.0,4.3.1)Maven10 Sept 2025
  • M
Deserialization of Untrusted Data
org.apache.jackrabbit:jackrabbit-core[,2.22.2)Maven10 Sept 2025
  • M
Deserialization of Untrusted Data
org.apache.jackrabbit:jackrabbit-jcr-commons[,2.22.2)Maven10 Sept 2025
  • M
Server-side Request Forgery (SSRF)
com.liferay.portal:com.liferay.portal.impl[,113.1.0)Maven7 Sept 2025
  • H
Denial of Service (DoS)
com.liferay:com.liferay.portal.workflow.kaleo.forms.web[,5.0.29)Maven7 Sept 2025
  • C
Deserialization of Untrusted Data
ai.h2o:h2o-core[,3.46.0.8)Maven5 Sept 2025
  • M
Arbitrary File Upload
com.vaadin:vaadin-upload-flow[2.0.0,14.13.1)[23.0.0,23.6.2)[24.0.0,24.7.7)Maven5 Sept 2025
  • M
Arbitrary File Upload
com.vaadin:vaadin-server[7.0.0,7.7.48)[8.0.0,8.28.2)Maven5 Sept 2025
  • M
Missing Authorization
org.jenkins-ci.plugins:global-build-stats[,347.v32a_eb_0493c4f)Maven4 Sept 2025
  • M
Insertion of Sensitive Information into Externally-Accessible File or Directory
org.jenkins-ci.plugins:git-client[,6.3.3)Maven4 Sept 2025
  • H
Improper Handling of Highly Compressed Data (Data Amplification)
io.netty:netty-codec-compression[,4.2.5.Final)Maven4 Sept 2025
  • H
Improper Handling of Highly Compressed Data (Data Amplification)
io.netty:netty-codec-http2[,4.1.125.Final)Maven4 Sept 2025
  • H
Improper Handling of Highly Compressed Data (Data Amplification)
io.netty:netty-codec-http[,4.1.125.Final)Maven4 Sept 2025
  • H
HTTP Request Smuggling
io.netty:netty-codec-http[,4.1.125.Final)[4.2.0.Alpha1,4.2.5.Final)Maven4 Sept 2025
  • H
Allocation of Resources Without Limits or Throttling (MadeYouReset)
io.undertow:undertow-core[,2.2.38.Final)[2.3.0.Alpha1,2.3.20.Final)Maven3 Sept 2025
  • C
Deserialization of Untrusted Data
ai.h2o:h2o-core[0,3.46.0.8)Maven2 Sept 2025
  • M
Relative Path Traversal
org.opencastproject:opencast-user-interface-configuration[0,]Maven31 Aug 2025
  • M
Missing Authorization
com.liferay:com.liferay.portal.workflow.kaleo.runtime.impl[,6.0.93)Maven31 Aug 2025
  • M
Command Injection
com.ritense.valtimo:core[,12.16.0.RELEASE)[13.0.0.RELEASE,13.1.2.RELEASE)Maven29 Aug 2025