Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Deserialization of Untrusted Data
org.apache.jackrabbit:jackrabbit-core[,2.22.2)Maven10 Sept 2025
  • M
Deserialization of Untrusted Data
org.apache.jackrabbit:jackrabbit-jcr-commons[,2.22.2)Maven10 Sept 2025
  • M
Server-side Request Forgery (SSRF)
com.liferay.portal:com.liferay.portal.impl[,113.1.0)Maven7 Sept 2025
  • H
Denial of Service (DoS)
com.liferay:com.liferay.portal.workflow.kaleo.forms.web[,5.0.29)Maven7 Sept 2025
  • C
Deserialization of Untrusted Data
ai.h2o:h2o-core[,3.46.0.8)Maven5 Sept 2025
  • M
Arbitrary File Upload
com.vaadin:vaadin-upload-flow[2.0.0,14.13.1)[23.0.0,23.6.2)[24.0.0,24.7.7)Maven5 Sept 2025
  • M
Arbitrary File Upload
com.vaadin:vaadin-server[7.0.0,7.7.48)[8.0.0,8.28.2)Maven5 Sept 2025
  • M
Missing Authorization
org.jenkins-ci.plugins:global-build-stats[,347.v32a_eb_0493c4f)Maven4 Sept 2025
  • M
Insertion of Sensitive Information into Externally-Accessible File or Directory
org.jenkins-ci.plugins:git-client[,6.3.3)Maven4 Sept 2025
  • H
Improper Handling of Highly Compressed Data (Data Amplification)
io.netty:netty-codec-compression[,4.2.5.Final)Maven4 Sept 2025
  • H
Improper Handling of Highly Compressed Data (Data Amplification)
io.netty:netty-codec-http2[,4.1.125.Final)Maven4 Sept 2025
  • H
Improper Handling of Highly Compressed Data (Data Amplification)
io.netty:netty-codec-http[,4.1.125.Final)Maven4 Sept 2025
  • H
HTTP Request Smuggling
io.netty:netty-codec-http[,4.1.125.Final)[4.2.0.Alpha1,4.2.5.Final)Maven4 Sept 2025
  • H
Allocation of Resources Without Limits or Throttling (MadeYouReset)
io.undertow:undertow-core[0,2.3.20.Final)Maven3 Sept 2025
  • C
Deserialization of Untrusted Data
ai.h2o:h2o-core[0,3.46.0.8)Maven2 Sept 2025
  • M
Relative Path Traversal
org.opencastproject:opencast-user-interface-configuration[0,]Maven31 Aug 2025
  • M
Missing Authorization
com.liferay:com.liferay.portal.workflow.kaleo.runtime.impl[,6.0.93)Maven31 Aug 2025
  • M
Command Injection
com.ritense.valtimo:core[,12.16.0.RELEASE)[13.0.0.RELEASE,13.1.2.RELEASE)Maven29 Aug 2025
  • M
Improper Neutralization
org.eclipse.angus:angus-mail[,2.0.4)Maven29 Aug 2025
  • H
XML External Entity (XXE) Injection
org.apache.tika:tika-parser-pdf-module[,3.2.2)Maven29 Aug 2025
  • M
Storing Passwords in a Recoverable Format
org.xwiki.platform:xwiki-platform-export-pdf-api[,16.4.8)[16.5.0-rc-1,16.10.7)[17.0.0-rc-1,17.4.0-rc-1)Maven29 Aug 2025
  • M
Files or Directories Accessible to External Parties
com.liferay:com.liferay.frontend.js.web[,5.0.125)Maven28 Aug 2025
  • M
Files or Directories Accessible to External Parties
com.liferay:com.liferay.object.dynamic.data.mapping.form.field.type[,1.0.65)Maven28 Aug 2025
  • M
Files or Directories Accessible to External Parties
com.liferay:com.liferay.object.web[,1.0.219)Maven28 Aug 2025
  • H
Allocation of Resources Without Limits or Throttling
org.webjars.bowergithub.mrrio:jspdf[0,]Maven27 Aug 2025
  • H
Allocation of Resources Without Limits or Throttling
org.webjars.bower:jspdf[0,]Maven27 Aug 2025
  • H
Allocation of Resources Without Limits or Throttling
org.webjars.bowergithub.parallax:jspdf[0,]Maven27 Aug 2025
  • H
Allocation of Resources Without Limits or Throttling
org.webjars.npm:jspdf[,3.0.3)Maven27 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.journal.service[,7.0.162)Maven27 Aug 2025
  • H
Privilege Defined With Unsafe Actions
org.apache.cassandra:cassandra-all[4.0.16,4.0.17)Maven27 Aug 2025