Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Prototype Pollution
CVE-2025-64718
Affects
org.webjars.bowergithub.nodeca:js-yaml
| Versions
[0,]
M
Prototype Pollution
CVE-2025-64718
Affects
org.webjars.npm:js-yaml
| Versions
[,4.1.1)
M
Prototype Pollution
CVE-2025-64718
Affects
org.webjars.bower:js-yaml
| Versions
[0,]
M
Prototype Pollution
CVE-2025-64718
Affects
org.webjars:js-yaml
| Versions
[0,]
L
Cross-site Scripting (XSS)
CVE-2025-59840
Affects
org.webjars.npm:vega-interpreter
| Versions
[0,]
L
Cross-site Scripting (XSS)
CVE-2025-59840
Affects
org.webjars.npm:vega-expression
| Versions
[0,]
L
Cross-site Scripting (XSS)
CVE-2025-59840
Affects
org.webjars.bowergithub.vega:vega
| Versions
[0,]
L
Cross-site Scripting (XSS)
CVE-2025-59840
Affects
org.webjars.bower:vega
| Versions
[0,]
L
Cross-site Scripting (XSS)
CVE-2025-59840
Affects
org.webjars.npm:vega
| Versions
[0,]
H
Improper Certificate Validation
CVE-2021-0341
Affects
com.squareup.okhttp3:okhttp
| Versions
[,4.9.2)
C
Arbitrary Code Injection
CVE-2025-64099
Affects
org.openidentityplatform.openam:openam-oauth2
| Versions
[,16.0.3)
H
XML External Entity (XXE) Injection
CVE-2025-64518
Affects
org.cyclonedx:cyclonedx-core-java
| Versions
[2.1.0,11.0.1)
H
Server-side Template Injection (SSTI)
Affects
freemarker:freemarker
| Versions
[0,]
H
XML External Entity (XXE) Injection
CVE-2025-10713
Affects
org.wso2.carbon.mediation:org.wso2.carbon.localentry
| Versions
[0,4.7.268)
C
Arbitrary Code Injection
CVE-2025-11093
Affects
org.apache.synapse:synapse-extensions
| Versions
[,4.0.0-wso2v255)
C
Arbitrary Code Injection
CVE-2025-11093
Affects
org.apache.synapse:synapse-core
| Versions
[,4.0.0-wso2v255)
L
Improper Validation of Integrity Check Value
Affects
io.github.ascopes:protobuf-maven-plugin
| Versions
[,4.0.2)
L
Missing Critical Step in Authentication
CVE-2025-12150
Affects
org.keycloak:keycloak-services
| Versions
[0,26.5.1)
M
Cross-site Scripting (XSS)
CVE-2025-62267
Affects
com.liferay:com.liferay.dynamic.data.mapping.item.selector.web
| Versions
[,1.0.9)
M
Missing Authorization
CVE-2025-62275
Affects
com.liferay:com.liferay.blogs.item.selector.web
| Versions
[,6.0.19)
H
Improper Validation of Certificate with Host Mismatch
CVE-2025-59250
Affects
com.microsoft.sqlserver:mssql-jdbc
| Versions
[,10.2.4.jre8)
[11.1.0.jre11-preview, 11.2.4.jre8)
[12.1.0.jre11-preview, 12.2.1.jre8)
[12.3.0.jre11-preview, 12.4.3.jre8)
[12.5.0.jre11-preview, 12.6.5.jre8)
[12.7.0.jre11-preview, 12.8.2.jre8)
[12.9.0.jre11-preview, 12.10.2.jre8)
[13.1.0.jre8-preview, 13.2.1.jre8)
M
Use of Web Browser Cache Containing Sensitive Information
CVE-2025-62276
Affects
com.liferay:com.liferay.adaptive.media.web
| Versions
[,5.0.52)
M
Use of Web Browser Cache Containing Sensitive Information
CVE-2025-62276
Affects
com.liferay.portal:com.liferay.portal.impl
| Versions
[,69.0.0)
M
Cross-site Scripting (XSS)
CVE-2025-62265
Affects
com.liferay:com.liferay.portal.security.iframe.sanitizer
| Versions
[,1.0.1)
M
Cross-site Scripting (XSS)
CVE-2025-62264
Affects
com.liferay:com.liferay.portal.language.override.web
| Versions
[,1.0.3)
M
Sensitive Information in Resource Not Removed Before Reuse
CVE-2025-11602
Affects
org.neo4j:neo4j-bolt
| Versions
[5.26.0,5.26.15)
[2025.10.1,2025.1.0)
M
CRLF Injection
CVE-2025-8419
Affects
org.keycloak:keycloak-services
| Versions
[,26.3.3)
H
Allocation of Resources Without Limits or Throttling
CVE-2025-55163
Affects
io.grpc:grpc-netty-shaded
| Versions
[,1.75.0)
M
Brute Force
CVE-2025-62257
Affects
com.liferay.portal:com.liferay.portal.impl
| Versions
[,60.0.0)
M
Cross-site Scripting (XSS)
CVE-2025-62263
Affects
com.liferay:com.liferay.account.admin.web
| Versions
[,2.0.108)