Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Server-side Request Forgery (SSRF)
com.liferay:com.liferay.portal.template.engine.api[,1.1.11)Maven12 Aug 2025
  • C
Deserialization of Untrusted Data
com.liferay.portal:release.portal.bom[,7.1.1)Maven11 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.frontend.js.spa.web[,1.0.14)Maven11 Aug 2025
  • C
Deserialization of Untrusted Data
org.apache.seata:seata-serializer[2.4.0,2.5.0)Maven11 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay.portal:release.portal.bom[7.4.3.70-ga70,7.4.3.74-ga74)Maven11 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay.portal:release.dxp.bom[7.4.13.u70,7.4.13.u74)Maven11 Aug 2025
  • C
Incorrect Authorization
com.liferay:com.liferay.portal.workflow.kaleo.definition.impl[,6.0.26)Maven11 Aug 2025
  • C
Incorrect Authorization
com.liferay:com.liferay.portal.workflow.kaleo.service[,6.0.78)Maven11 Aug 2025
  • C
Incorrect Authorization
com.liferay:com.liferay.portal.workflow.kaleo.api[,13.4.0)Maven11 Aug 2025
  • M
Open Redirect
com.liferay.portal:release.portal.bom[7.4.3.70-ga70,7.4.3.77-ga77)Maven11 Aug 2025
  • M
Open Redirect
com.liferay.portal:release.dxp.bom[7.4.13.u70,7.4.13.u77)Maven11 Aug 2025
  • H
Cross-site Request Forgery (CSRF)
com.liferay.portal:release.portal.bom[7.4.3.70-ga70,7.4.3.77-ga77)Maven11 Aug 2025
  • H
Cross-site Request Forgery (CSRF)
com.liferay.portal:release.dxp.bom[7.4.13.u70,7.4.13.u77)Maven11 Aug 2025
  • H
Deserialization of Untrusted Data
org.apache.cxf:cxf-rt-transports-jms[,3.6.8)[4.0.0,4.0.9)[4.1.0,4.1.3)Maven10 Aug 2025
  • H
Memory Allocation with Excessive Size Value
io.undertow:undertow-core[,2.2.27.Final)[2.3.0.Alpha1,2.3.9.Final)Maven8 Aug 2025
  • M
Improper Neutralization
org.eclipse.angus:smtp[,2.0.4)Maven8 Aug 2025
  • M
Information Exposure
org.opensearch.plugin:opensearch-security[,2.19.3.0)Maven8 Aug 2025
  • M
Information Exposure
org.opensearch.plugin:opensearch-security[,2.19.3.0)Maven8 Aug 2025
  • H
Use After Free
org.webjars.npm:electron[0,]Maven7 Aug 2025
  • M
Improper Output Neutralization for Logs
org.apache.struts:struts-extras[0,]Maven7 Aug 2025
  • M
CRLF Injection
org.keycloak:keycloak-server-spi-private[,26.3.3)Maven7 Aug 2025
  • H
Prototype Pollution
org.webjars.bower:linkifyjs[0,]Maven7 Aug 2025
  • H
Prototype Pollution
org.webjars.npm:linkifyjs[,4.3.2)Maven7 Aug 2025
  • M
Insertion of Sensitive Information into Log File
com.kuzudb:kuzu[,0.8.2)Maven7 Aug 2025
  • M
Symlink Attack
org.webjars.npm:tmp[0,]Maven7 Aug 2025
  • H
Cross-site Scripting (XSS)
io.kestra:ui[,0.22.0)Maven6 Aug 2025
  • H
Incorrect Permission Assignment for Critical Resource
org.apache.apisix:apisix-plugin-runner[,0.6.0)Maven6 Aug 2025
  • M
Access Control Bypass
org.dromara:northstar[0,]Maven6 Aug 2025
  • H
Improper Validation of Specified Type of Input
org.apache.zeppelin:zeppelin-jdbc[0.11.1,0.12.0)Maven5 Aug 2025
  • M
Cross-site Scripting (XSS)
org.apache.zeppelin:zeppelin-web[,0.12.0)Maven5 Aug 2025