Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • C
Eval Injection
org.xwiki.platform:xwiki-platform-search-solr-ui[7.2-rc-1,14.10.20)[15.0-rc-1,15.5.4)[15.6-rc-1,15.10-rc-1)Maven11 Apr 2024
  • C
Cross-Site Request Forgery (CSRF)
org.xwiki.platform:xwiki-platform-scheduler-ui[3.1,14.10.19)[15.0-rc-1,15.5.4)[15.6-rc-1,15.9)Maven11 Apr 2024
  • C
Cross-Site Request Forgery (CSRF)
org.xwiki.platform:xwiki-platform-realtime-webjar[,14.10.19)[15.0-rc-1,15.5.4)[15.6-rc-1,15.9)Maven11 Apr 2024
  • C
Cross-Site Request Forgery (CSRF)
org.xwiki.platform:xwiki-platform-realtime-ui[,14.10.19)[15.0-rc-1,15.5.4)[15.6-rc-1,15.9)Maven11 Apr 2024
  • C
Eval Injection
org.xwiki.platform:xwiki-platform-search-ui[,14.10.20)[15.0-rc-1,15.5.4)[15.6-rc-1,15.10-rc-1)Maven11 Apr 2024
  • C
Eval Injection
org.xwiki.commons:xwiki-commons-velocity[,14.10.19)[15.0-rc-1,15.5.4)[15.6-rc-1,15.9-rc-1)Maven11 Apr 2024
  • M
Cross-Site Request Forgery (CSRF)
org.xwiki.platform:xwiki-platform-scheduler-ui[3.1,14.10.19)[15.0-rc-1,15.5.4)[15.6-rc-1,15.9)Maven11 Apr 2024
  • C
Improper Control of Generation of Code ('Code Injection')
org.xwiki.platform:xwiki-platform-search-ui[5.2-milestone-2,14.10.20)[15.0-rc-1,15.5.4)[15.6-rc-1,15.10-rc-1)Maven11 Apr 2024
  • M
Improper Input Validation
org.apache.zeppelin:zeppelin-interpreter[0.8.2,0.11.1)Maven11 Apr 2024
  • M
Improper Input Validation
org.apache.zeppelin:zeppelin-server[0.8.2,0.11.1)Maven11 Apr 2024
  • M
Improper Input Validation
org.apache.zeppelin:zeppelin-server[,0.8.2,0.11.1)Maven11 Apr 2024
  • C
Missing Authorization
org.xwiki.platform:xwiki-platform-localization-source-wiki[4.3-milestone-2,14.10.20)[15.0-rc-1,15.5.4)[15.6-rc-1,15.10-rc-1)Maven11 Apr 2024
  • M
Information Exposure
org.xwiki.platform:xwiki-platform-oldcore[5.0-rc-1,14.10.19)[15.0-rc-1,15.5.4)[15.6-rc-1,15.9-rc-1)Maven11 Apr 2024
  • C
Missing Authorization
org.xwiki.platform:xwiki-platform-oldcore[3.0.1,14.10.20)[15.0-rc-1,15.5.4)[15.6-rc-1,15.10-rc-1)Maven11 Apr 2024
  • M
Template Injection
org.webjars.npm:dompurify[,2.5.0)[3.0.1,3.1.0)Maven11 Apr 2024
  • M
Template Injection
org.webjars.bower:dompurify[0,]Maven11 Apr 2024
  • M
Template Injection
org.webjars.bowergithub.cure53:dompurify[0,]Maven11 Apr 2024
  • H
Regular Expression Denial of Service (ReDoS)
org.webjars.npm:xlsx[0,]Maven10 Apr 2024
  • M
Improper Validation of Syntactic Correctness of Input
org.apache.zeppelin:zeppelin-server[0.10.1,0.11.0)Maven10 Apr 2024
  • M
Cross-Site Request Forgery (CSRF)
org.apache.zeppelin:zeppelin-web[,0.9.0)Maven10 Apr 2024
  • M
Path Traversal
org.apache.zeppelin:zeppelin-server[0.9.0,0.11.0)Maven10 Apr 2024
  • H
Improper Authentication
org.eclipse.kura:org.eclipse.kura.web2[2.0.600,]Maven10 Apr 2024
  • M
Authentication Bypass by Spoofing
org.apache.zeppelin:zeppelin-server[0.10.1,0.11.0)Maven10 Apr 2024
  • M
Improper Input Validation
org.apache.zeppelin:sap[0.8.0,]Maven9 Apr 2024
  • H
Improper Neutralization of Special Elements Used in a Template Engine
com.xuxueli:xxl-job-core[0,2.4.1)Maven7 Apr 2024
  • H
Improper Input Validation
io.undertow:undertow-core[,2.2.32.Final)[2.3.0.Alpha1,2.3.13.Final)Maven5 Apr 2024
  • M
Improper Authorization
org.apache.pulsar:pulsar-broker-common[2.7.1, 3.0.4)[3.1.0, 3.2.2)Maven3 Apr 2024
  • M
Improper Authorization
org.apache.pulsar:pulsar-broker[2.7.1, 3.0.4)[3.1.0, 3.2.2)Maven3 Apr 2024
  • C
Deserialization of Untrusted Data
org.codehaus.groovy:groovy[,2.4.7)Maven2 Apr 2024
  • C
Deserialization of Untrusted Data
org.codehaus.groovy:groovy[1.7.0,2.4.4)Maven2 Apr 2024