Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Incorrect Permission Assignment for Critical Resource
com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary[,1.0.23)Maven16 Oct 2025
  • M
Directory Traversal
org.zwobble.mammoth:mammoth[,1.11.0)Maven16 Oct 2025
  • M
Cross-site Scripting
org.apache.geode:geode-web-api[,1.15.2)Maven15 Oct 2025
  • C
Improper Verification of Cryptographic Signature
org.apache.spark:spark-network-common_2.13[,3.4.4)[3.5.0,3.5.2)Maven15 Oct 2025
  • C
Improper Verification of Cryptographic Signature
org.apache.spark:spark-network-common_2.12[,3.4.4)[3.5.0,3.5.2)Maven15 Oct 2025
  • M
Incorrect Authorization
com.liferay:com.liferay.change.tracking.web[,2.0.121)Maven14 Oct 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay:com.liferay.change.tracking.web[,2.0.120)Maven14 Oct 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay:com.liferay.account.api[,18.2.0)Maven14 Oct 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay:com.liferay.account.service[,2.0.119)Maven14 Oct 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay:com.liferay.account.admin.web[,2.0.115)Maven14 Oct 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay.commerce:com.liferay.commerce.service[,11.0.162)Maven14 Oct 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay.commerce:com.liferay.commerce.shipment.web[,4.0.64)Maven14 Oct 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay.portal:com.liferay.portal.impl[,99.0.1)Maven14 Oct 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.mentions.web[,6.0.35)Maven14 Oct 2025
  • M
Incorrect Execution-Assigned Permissions
org.apache.streampark:streampark[2.1.4,]Maven13 Oct 2025
  • M
Cross-site Request Forgery (CSRF)
com.liferay:com.liferay.change.tracking.web[2.0.9,2.0.121)Maven13 Oct 2025
  • M
SQL Injection
org.apache.flink:flink-cdc-pipeline-connector-oceanbase[3.0.0,3.5.0)Maven13 Oct 2025
  • M
SQL Injection
org.apache.flink:flink-connector-sqlserver-cdc[3.0.0,3.5.0)Maven13 Oct 2025
  • M
SQL Injection
org.apache.flink:flink-connector-oracle-cdc[3.0.0,3.5.0)Maven13 Oct 2025
  • M
SQL Injection
org.apache.flink:flink-connector-mysql-cdc[3.0.0,3.5.0)Maven13 Oct 2025
  • M
SQL Injection
org.apache.flink:flink-connector-db2-cdc[3.0.0,3.5.0)Maven13 Oct 2025
  • M
SQL Injection
org.apache.flink:flink-cdc-pipeline-connector-mysql[3.0.0,3.5.0)Maven13 Oct 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.workflow.kaleo.designer.web[5.0.56, 5.0.124)Maven13 Oct 2025
  • M
Missing Authorization
tech.powerjob:powerjob-server-starter[0,]Maven12 Oct 2025
  • M
Missing Authorization
tech.powerjob:powerjob-server-starter[0,]Maven12 Oct 2025
  • M
Cross-site Scripting (XSS)
com.liferay.commerce:com.liferay.commerce.term.service[,1.0.45)Maven12 Oct 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.calendar.web[5.0.45, 5.0.88)Maven12 Oct 2025
  • M
Cross-site Scripting (XSS)
com.liferay.commerce:com.liferay.commerce.order.web[5.0.29,5.0.101)Maven12 Oct 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.account.admin.web[2.0.30,2.0.114)Maven12 Oct 2025
  • M
Cross-site Scripting (XSS)
com.liferay.commerce:com.liferay.commerce.product.service[6.0.5,6.0.134)Maven10 Oct 2025