Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Cross-site Scripting (XSS)
CVE-2025-43791
Affects
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
| Versions
[,6.0.161)
H
Timing Attack
CVE-2025-59432
Affects
com.ongres.scram:scram-common
| Versions
[,3.2)
M
Cross-site Scripting (XSS)
CVE-2025-43787
Affects
com.liferay:com.liferay.users.admin.web
| Versions
[0,]
M
Cross-site Scripting (XSS)
CVE-2025-43794
Affects
com.liferay:com.liferay.portal.settings.web
| Versions
[,5.0.53)
H
Deserialization of Untrusted Data
CVE-2025-59328
Affects
org.apache.fory:fory-core
| Versions
[,0.12.2)
M
Use of Default Credentials
CVE-2025-43799
Affects
com.liferay.portal:com.liferay.portal.impl
| Versions
[,97.0.0)
L
External Control of System or Configuration Setting
CVE-2025-43792
Affects
com.liferay.portal:com.liferay.portal.kernel
| Versions
[,130.0.1)
L
External Control of System or Configuration Setting
CVE-2025-43792
Affects
com.liferay:com.liferay.staging.taglib
| Versions
[,8.0.4)
M
Improper Validation of Specified Quantity in Input
CVE-2025-43793
Affects
com.liferay:com.liferay.cookies.impl
| Versions
[,1.0.12)
H
Improper Encoding or Escaping of Output
CVE-2025-57665
Affects
org.webjars.npm:element-plus
| Versions
[0,]
H
Authorization Bypass Through User-Controlled Key
CVE-2025-43790
Affects
com.liferay:com.liferay.object.service
| Versions
[,1.0.197)
H
Improper Resource Shutdown or Release
CVE-2025-58369
Affects
co.fs2:fs2-io_3
| Versions
[,2.5.13)
[3.0.0,3.12.1)
[3.13.0-M1,3.13.0-M7)
H
Improper Resource Shutdown or Release
CVE-2025-58369
Affects
co.fs2:fs2-io_2.13
| Versions
[,2.5.13)
[3.0.0,3.12.1)
[3.13.0-M1,3.13.0-M7)
H
Improper Resource Shutdown or Release
CVE-2025-58369
Affects
co.fs2:fs2-io_2.12
| Versions
[,2.5.13)
[3.0.0,3.12.1)
[3.13.0-M1,3.13.0-M7)
M
Missing Authorization
CVE-2025-58460
Affects
io.jenkins.plugins:opentelemetry
| Versions
[,3.1543.1545.vf5a_4ec123769)
M
Incorrect Authorization
CVE-2025-43784
Affects
com.liferay:com.liferay.headless.builder.impl
| Versions
[,1.0.32)
M
Cross-site Scripting (XSS)
CVE-2025-43783
Affects
com.liferay:com.liferay.frontend.editor.ckeditor.web
| Versions
[5.0.7,5.0.101)
M
Cross-site Scripting (XSS)
CVE-2025-10044
Affects
org.keycloak:keycloak-ui-shared
| Versions
[,26.3.4)
M
Cross-site Scripting (XSS)
CVE-2025-43778
Affects
com.liferay:com.liferay.portal.workflow.kaleo.forms.web
| Versions
[5.0.3,5.0.107)
M
Cross-site Scripting (XSS)
CVE-2025-43775
Affects
com.liferay:com.liferay.client.extension.web
| Versions
[,1.0.71)
M
Timing Attack
CVE-2025-43786
Affects
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl
| Versions
[5.0.23,5.0.50)
M
Timing Attack
CVE-2025-43786
Affects
com.liferay:com.liferay.portal.vulcan.impl
| Versions
[5.0.7,5.0.127)
M
Timing Attack
CVE-2025-43786
Affects
com.liferay:com.liferay.headless.admin.workflow.impl
| Versions
[5.0.4,5.0.83)
M
Timing Attack
CVE-2025-43786
Affects
com.liferay:com.liferay.portal.workflow.api
| Versions
[7.0.1,11.0.1)
M
Cross-site Scripting (XSS)
CVE-2025-43781
Affects
com.liferay:com.liferay.portal.search.web
| Versions
[6.0.125,6.0.143)
M
Allocation of Resources Without Limits or Throttling
CVE-2025-58754
Affects
org.webjars.bower:axios
| Versions
[0,]
M
Allocation of Resources Without Limits or Throttling
CVE-2025-58754
Affects
org.webjars.bowergithub.axios:axios
| Versions
[0,]
M
Allocation of Resources Without Limits or Throttling
CVE-2025-58754
Affects
org.webjars.npm:axios
| Versions
[,0.30.2)
[1.1.2,1.12.2)
M
Cross-site Scripting (XSS)
CVE-2025-43785
Affects
com.liferay:com.liferay.portal.workflow.task.web
| Versions
[,5.0.76)
M
Information Exposure
CVE-2025-43777
Affects
com.liferay:com.liferay.portal.security.sso.openid.connect.impl
| Versions
[0,]