Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Arbitrary File Upload
CVE-2021-33990
Affects
com.liferay.portal:portal-service
| Versions
[,6.2.5)
L
Missing Authorization
CVE-2025-62247
Affects
com.liferay:com.liferay.search.experiences.service
| Versions
[0,]
L
Predictable Seed in Pseudo-Random Number Generator (PRNG)
CVE-2025-62710
Affects
org.sakaiproject.scheduler:scheduler-component-shared
| Versions
[0,]
L
Predictable Seed in Pseudo-Random Number Generator (PRNG)
CVE-2025-62710
Affects
org.sakaiproject.kernel:sakai-kernel-impl
| Versions
[0,]
H
Files or Directories Accessible to External Parties
CVE-2025-11965
Affects
io.vertx:vertx-web
| Versions
[,4.5.22)
[5.0.0.CR1,5.0.5)
L
Cross-site Scripting (XSS)
CVE-2025-11966
Affects
io.vertx:vertx-web
| Versions
[,4.5.22)
[5.0.0.CR1,5.0.5)
H
Improper Verification of Cryptographic Signature
CVE-2025-53057
Affects
org.graalvm.sdk:graal-sdk
| Versions
[,17.0.17)
[21.0.0,21.0.9)
M
Improper Input Validation
CVE-2025-61748
Affects
org.graalvm.sdk:graal-sdk
| Versions
[,21.0.9)
M
Origin Validation Error
CVE-2025-62250
Affects
com.liferay:com.liferay.portal.cluster.multiple
| Versions
[,5.0.35)
M
Cross-site Scripting (XSS)
CVE-2025-62249
Affects
com.liferay.portal:com.liferay.portal.impl
| Versions
[0,]
H
Improper Isolation or Compartmentalization
CVE-2025-57738
Affects
org.apache.syncope.fit:syncope-fit-build-tools
| Versions
[,3.0.14)
[4.0.0,4.0.2)
H
Improper Isolation or Compartmentalization
CVE-2025-57738
Affects
org.apache.syncope.core:syncope-core-provisioning-java
| Versions
[,3.0.14)
[4.0.0,4.0.2)
H
Improper Isolation or Compartmentalization
CVE-2025-57738
Affects
org.apache.syncope.core:syncope-core-persistence-api
| Versions
[,3.0.14)
[4.0.0,4.0.2)
H
Improper Isolation or Compartmentalization
CVE-2025-57738
Affects
org.apache.syncope.core:syncope-core-spring
| Versions
[,3.0.14)
[4.0.0,4.0.2)
M
SQL Injection
CVE-2025-56316
Affects
net.mingsoft:ms-mcms
| Versions
[,6.0.2)
M
Cross-site Request Forgery (CSRF)
CVE-2025-47410
Affects
org.apache.geode:geode-web
| Versions
[,1.15.2)
C
Improper Certificate Validation
CVE-2025-62371
Affects
org.opensearch.dataprepper.plugins:kafka-plugins
| Versions
[,2.12.2)
C
Improper Certificate Validation
CVE-2025-62371
Affects
org.opensearch.dataprepper.plugins:geoip-processor
| Versions
[,2.12.2)
C
Improper Certificate Validation
CVE-2025-62371
Affects
org.opensearch.dataprepper.plugins:opensearch
| Versions
[,2.12.2)
M
Cross-site Request Forgery (CSRF)
CVE-2025-41254
Affects
org.springframework:spring-websocket
| Versions
[,6.2.12)
H
Expression Language Injection
CVE-2025-41253
Affects
org.springframework.cloud:spring-cloud-gateway-server
| Versions
[,4.2.6)
[4.3.0,4.3.2)
M
CRLF Injection
CVE-2025-59419
Affects
io.netty:netty-codec-smtp
| Versions
[,4.1.128.Final)
[4.2.0.Alpha1,4.2.7.Final)
M
Incorrect Permission Assignment for Critical Resource
CVE-2025-62251
Affects
com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary
| Versions
[,1.0.23)
M
Directory Traversal
CVE-2025-11849
Affects
org.zwobble.mammoth:mammoth
| Versions
[,1.11.0)
M
Cross-site Scripting
CVE-2024-44088
Affects
org.apache.geode:geode-web-api
| Versions
[,1.15.2)
C
Improper Verification of Cryptographic Signature
CVE-2025-55039
Affects
org.apache.spark:spark-network-common_2.13
| Versions
[,3.4.4)
[3.5.0,3.5.2)
C
Improper Verification of Cryptographic Signature
CVE-2025-55039
Affects
org.apache.spark:spark-network-common_2.12
| Versions
[,3.4.4)
[3.5.0,3.5.2)
M
Incorrect Authorization
CVE-2025-62243
Affects
com.liferay:com.liferay.change.tracking.web
| Versions
[,2.0.121)
M
Authorization Bypass Through User-Controlled Key
CVE-2025-62244
Affects
com.liferay:com.liferay.change.tracking.web
| Versions
[,2.0.120)
M
Authorization Bypass Through User-Controlled Key
CVE-2025-62242
Affects
com.liferay:com.liferay.account.api
| Versions
[,18.2.0)