Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • C
Incorrect Authorization
com.liferay:com.liferay.portal.workflow.kaleo.api[,13.4.0)Maven11 Aug 2025
  • M
Open Redirect
com.liferay.portal:release.portal.bom[7.4.3.70-ga70,7.4.3.77-ga77)Maven11 Aug 2025
  • M
Open Redirect
com.liferay.portal:release.dxp.bom[7.4.13.u70,7.4.13.u77)Maven11 Aug 2025
  • H
Cross-site Request Forgery (CSRF)
com.liferay.portal:release.portal.bom[7.4.3.70-ga70,7.4.3.77-ga77)Maven11 Aug 2025
  • H
Cross-site Request Forgery (CSRF)
com.liferay.portal:release.dxp.bom[7.4.13.u70,7.4.13.u77)Maven11 Aug 2025
  • H
Deserialization of Untrusted Data
org.apache.cxf:cxf-rt-transports-jms[,3.6.8)[4.0.0,4.0.9)[4.1.0,4.1.3)Maven10 Aug 2025
  • H
Memory Allocation with Excessive Size Value
io.undertow:undertow-core[,2.2.27.Final)[2.3.0.Alpha1,2.3.9.Final)Maven8 Aug 2025
  • M
Improper Neutralization
org.eclipse.angus:smtp[,2.0.4)Maven8 Aug 2025
  • M
Information Exposure
org.opensearch.plugin:opensearch-security[,2.19.3.0)Maven8 Aug 2025
  • M
Information Exposure
org.opensearch.plugin:opensearch-security[,2.19.3.0)Maven8 Aug 2025
  • H
Use After Free
org.webjars.npm:electron[0,]Maven7 Aug 2025
  • M
Improper Output Neutralization for Logs
org.apache.struts:struts-extras[0,]Maven7 Aug 2025
  • M
CRLF Injection
org.keycloak:keycloak-server-spi-private[0,]Maven7 Aug 2025
  • H
Prototype Pollution
org.webjars.bower:linkifyjs[0,]Maven7 Aug 2025
  • H
Prototype Pollution
org.webjars.npm:linkifyjs[0,]Maven7 Aug 2025
  • M
Insertion of Sensitive Information into Log File
com.kuzudb:kuzu[,0.8.2)Maven7 Aug 2025
  • M
Symlink Attack
org.webjars.npm:tmp[0,]Maven7 Aug 2025
  • H
Cross-site Scripting (XSS)
io.kestra:ui[,0.22.0)Maven6 Aug 2025
  • H
Incorrect Permission Assignment for Critical Resource
org.apache.apisix:apisix-plugin-runner[,0.6.0)Maven6 Aug 2025
  • M
Access Control Bypass
org.dromara:northstar[0,]Maven6 Aug 2025
  • H
Improper Validation of Specified Type of Input
org.apache.zeppelin:zeppelin-jdbc[0.11.1,0.12.0)Maven5 Aug 2025
  • M
Cross-site Scripting (XSS)
org.apache.zeppelin:zeppelin-web[,0.12.0)Maven5 Aug 2025
  • M
Missing Origin Validation in WebSockets
org.apache.zeppelin:zeppelin-shell[,0.12.0)Maven5 Aug 2025
  • H
Cleartext Storage of Sensitive Information
com.ibm.devops:ibm-cloud-devops[0,]Maven4 Aug 2025
  • H
Arbitrary Command Injection
org.webjars.npm:network[0,]Maven4 Aug 2025
  • M
Cross-site Scripting
org.fujion.webjars:bootstrap[0,]Maven4 Aug 2025
  • M
Cross-site Scripting
org.webjars.bowergithub.jasny:bootstrap[,4.0.0)Maven4 Aug 2025
  • L
Regular Expression Denial of Service (ReDoS)
org.webjars.npm:html-dom-parser[0,]Maven3 Aug 2025
  • M
Cross-site Scripting (XSS)
org.apache.jspwiki:jspwiki-main[,2.12.3)Maven1 Aug 2025
  • M
Open Redirect
com.liferay.portal:com.liferay.portal.impl[,25.0.0)Maven30 Jul 2025