Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • L
Cross-site Scripting (XSS)
com.liferay:com.liferay.knowledge.base.web[,5.0.109)Maven24 Oct 2025
  • M
Missing Authorization
com.liferay:com.liferay.portal.vulcan.impl[,5.0.110)Maven24 Oct 2025
  • M
Missing Authorization
com.liferay:com.liferay.portal.security.auth.verifier[,6.0.26)Maven24 Oct 2025
  • M
Insufficient Session Expiration
org.keycloak:keycloak-services[,26.3.0)Maven24 Oct 2025
  • M
Arbitrary File Upload
com.liferay.portal:portal-web[,6.2.1)Maven23 Oct 2025
  • M
Arbitrary File Upload
com.liferay.portal:portal-service[,6.2.5)Maven23 Oct 2025
  • L
Missing Authorization
com.liferay:com.liferay.search.experiences.service[0,]Maven23 Oct 2025
  • L
Predictable Seed in Pseudo-Random Number Generator (PRNG)
org.sakaiproject.scheduler:scheduler-component-shared[0,]Maven23 Oct 2025
  • L
Predictable Seed in Pseudo-Random Number Generator (PRNG)
org.sakaiproject.kernel:sakai-kernel-impl[0,]Maven23 Oct 2025
  • H
Files or Directories Accessible to External Parties
io.vertx:vertx-web[,4.5.22)[5.0.0.CR1,5.0.5)Maven23 Oct 2025
  • L
Cross-site Scripting (XSS)
io.vertx:vertx-web[,4.5.22)[5.0.0.CR1,5.0.5)Maven23 Oct 2025
  • H
Improper Verification of Cryptographic Signature
org.graalvm.sdk:graal-sdk[,17.0.17)[21.0.0,21.0.9)Maven22 Oct 2025
  • M
Improper Input Validation
org.graalvm.sdk:graal-sdk[,21.0.9)Maven22 Oct 2025
  • M
Origin Validation Error
com.liferay:com.liferay.portal.cluster.multiple[,5.0.35)Maven22 Oct 2025
  • M
Cross-site Scripting (XSS)
com.liferay.portal:com.liferay.portal.impl[0,]Maven22 Oct 2025
  • H
Improper Isolation or Compartmentalization
org.apache.syncope.fit:syncope-fit-build-tools[,3.0.14)[4.0.0,4.0.2)Maven21 Oct 2025
  • H
Improper Isolation or Compartmentalization
org.apache.syncope.core:syncope-core-provisioning-java[,3.0.14)[4.0.0,4.0.2)Maven21 Oct 2025
  • H
Improper Isolation or Compartmentalization
org.apache.syncope.core:syncope-core-persistence-api[,3.0.14)[4.0.0,4.0.2)Maven21 Oct 2025
  • H
Improper Isolation or Compartmentalization
org.apache.syncope.core:syncope-core-spring[,3.0.14)[4.0.0,4.0.2)Maven21 Oct 2025
  • M
SQL Injection
net.mingsoft:ms-mcms[,6.0.2)Maven20 Oct 2025
  • M
Cross-site Request Forgery (CSRF)
org.apache.geode:geode-web[,1.15.2)Maven20 Oct 2025
  • C
Improper Certificate Validation
org.opensearch.dataprepper.plugins:kafka-plugins[,2.12.2)Maven19 Oct 2025
  • C
Improper Certificate Validation
org.opensearch.dataprepper.plugins:geoip-processor[,2.12.2)Maven19 Oct 2025
  • C
Improper Certificate Validation
org.opensearch.dataprepper.plugins:opensearch[,2.12.2)Maven19 Oct 2025
  • M
Cross-site Request Forgery (CSRF)
org.springframework:spring-websocket[,6.2.12)Maven17 Oct 2025
  • H
Expression Language Injection
org.springframework.cloud:spring-cloud-gateway-server[,4.2.6)[4.3.0,4.3.2)Maven16 Oct 2025
  • M
CRLF Injection
io.netty:netty-codec-smtp[,4.1.128.Final)[4.2.0.Alpha1,4.2.7.Final)Maven16 Oct 2025
  • M
Incorrect Permission Assignment for Critical Resource
com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary[,1.0.23)Maven16 Oct 2025
  • M
Directory Traversal
org.zwobble.mammoth:mammoth[,1.11.0)Maven16 Oct 2025
  • M
Cross-site Scripting
org.apache.geode:geode-web-api[,1.15.2)Maven15 Oct 2025