Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.change.tracking.service[,3.0.91)Maven23 Sept 2025
  • M
Deserialization of Untrusted Data
ai.h2o:h2o-core[0,]Maven23 Sept 2025
  • M
Deserialization of Untrusted Data
ai.h2o:h2o-core[0,]Maven23 Sept 2025
  • C
Deserialization of Untrusted Data
ai.h2o:h2o-core[0,3.46.0.8)Maven23 Sept 2025
  • M
Cross-site Request Forgery (CSRF)
com.liferay.portal:portal-service[,6.1.0)Maven22 Sept 2025
  • M
Cross-site Request Forgery (CSRF)
com.liferay.portal:portal-impl[,6.1.0)Maven22 Sept 2025
  • M
Incorrect Permission Assignment for Critical Resource
com.liferay.commerce:com.liferay.commerce.product.type.virtual.service[,4.0.46)Maven22 Sept 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay:com.liferay.portal.workflow.kaleo.service[,6.0.82)Maven21 Sept 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl[,5.0.48)Maven21 Sept 2025
  • C
Incorrect Default Permissions
org.apache.dolphinscheduler:dolphinscheduler[,3.3.1)Maven19 Sept 2025
  • M
Log Injection
io.jenkins.lib:support-log-formatter[,1.3.1)Maven18 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.search.web[,6.0.124)Maven18 Sept 2025
  • M
Unchecked Input for Loop Condition
com.liferay.portal:com.liferay.portal.impl[,96.0.0)Maven18 Sept 2025
  • M
Missing Authorization
org.jenkins-ci.main:jenkins-core[,2.516.3)[2.517,2.528)Maven18 Sept 2025
  • M
Missing Authorization
org.jenkins-ci.main:jenkins-core[,2.516.3)[2.517,2.528)Maven18 Sept 2025
  • C
Improper Neutralization of Special Elements Used in a Template Engine
com.hubspot.jinjava:jinjava[,2.8.1)Maven18 Sept 2025
  • C
Command Injection
org.apache.dolphinscheduler:dolphinscheduler-alert-script[,3.3.1)Maven18 Sept 2025
  • M
Missing Critical Step in Authentication
com.liferay:com.liferay.multi.factor.authentication.timebased.otp.web[,2.0.25)Maven18 Sept 2025
  • H
Incorrect Authorization
org.springframework.security:spring-security-core[6.4.4,6.4.10)[6.5.0,6.5.4)Maven17 Sept 2025
  • H
Incorrect Authorization
org.springframework:spring-core[,6.2.11)Maven17 Sept 2025
  • L
Incorrect Authorization
com.liferay.commerce:com.liferay.commerce.service[,11.0.168)Maven17 Sept 2025
  • L
Incorrect Authorization
com.liferay:com.liferay.comment.web[,6.1.4)Maven17 Sept 2025
  • M
Missing Authorization
com.liferay:com.liferay.organizations.item.selector.web[,4.0.22)Maven17 Sept 2025
  • M
Open Redirect
com.liferay.portal:com.liferay.portal.impl[,93.0.0)Maven17 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.object.web[,1.0.194)Maven17 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.dynamic.data.mapping.form.field.type[,6.0.161)Maven17 Sept 2025
  • H
Timing Attack
com.ongres.scram:scram-common[,3.2)Maven17 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.users.admin.web[0,]Maven17 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.settings.web[,5.0.53)Maven17 Sept 2025
  • H
Deserialization of Untrusted Data
org.apache.fory:fory-core[,0.12.2)Maven17 Sept 2025