Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.28% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's… | |
| Analizada | Media (5.3) | 0.44% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password. | |
| Analizada | Media (5.3) | 0.53% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the… | |
| Analizada | Media (5.3) | 0.53% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily… | |
| Analizada | Media (6.5) | 0.71% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote… | |
| Analizada | Media (5.4) | 0.52% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (6.1) | 0.36% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two forward slashes, which allows remote attackers to redirect users to… | |
| Analizada | Media (6.1) | 0.96% | 💥 Exploit | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to… | |
| Analizada | Alta (7.5) | 0.33% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack… | |
| Analizada | Alta (8.7) | 0.50% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume… | |
| Analizada | Media (5.3) | 0.48% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any… | |
| Analizada | Media (6.5) | 0.41% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission… | |
| Analizada | Media (4.3) | 0.44% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user's full name from the page's title by… | |
| Analizada | Media (5.4) | 0.33% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled, which allows remote… | |
| Analizada | Media (6.1) | 0.39% | — | Liferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter. | |
| Analizada | Media (6.1) | 0.39% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the… | |
| Modificada | Media (6.3) | 0.48% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page. | |
| Analizada | Alta (7.3) | 0.44% | — | Oracle Agile Product Lifecycle Management FOR Process | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). Supported versions that are affected are Prior to 6.2.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile… | |
| Analizada | Alta (8.8) | 3.9% | ⚠ Explotación activa | Oracle Agile Product Lifecycle Management | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in… | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Battery Life Diagnostic Tool | 14/2/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.66% | — | IBM Engineering Lifecycle Optimization | 9/2/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755. | |
| Modificada | Media (6.1) | 0.26% | — | IBM Engineering Lifecycle Optimization | 9/2/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM… | |
| Modificada | Alta (8.8) | 0.38% | — | IBM Engineering Lifecycle Optimization | 9/2/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 268749. | |
| Modificada | Alta (8.1) | 0.55% | — | Liferay Digital Experience PlatformLiferay DXPLiferay Portal | 8/2/2024 | 17/6/2026 | In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user. This may allow… | |
| Modificada | Media (5.3) | 0.59% | — | Liferay Digital Experience PlatformLiferay DXPLiferay Portal | 8/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows… |