Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
2016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 30/9/2025 | 17/6/2026 | Vulnerabilidades de cross-site scripting (XSS) almacenadas en la traducción de Contenido Web en Liferay Portal 7.4.0 hasta 7.4.3.112, y versiones anteriores no compatibles, y Liferay DXP 2023.Q4.0 hasta 2023.Q4.8, 2023.Q3.1 hasta 2023.Q3.10, 7.4 GA hasta la actualización 92, y versiones anteriores no compatibles,… | |
| Analizada | Media (5.3) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 30/9/2025 | 17/6/2026 | Vulnerabilidad de Referencia Directa a Objeto Insegura (IDOR) con eventos de auditoría en Liferay Portal 7.4.0 hasta 7.4.3.117, y versiones antiguas no compatibles, y Liferay DXP 2024.Q1.1 hasta 2024.Q1.5, 2023.Q4.0 hasta 2023.Q4.10, 2023.Q3.1 hasta 2023.Q3.10, 7.4 GA hasta la actualización 92, y versiones antiguas no… | |
| Analizada | Media (4.8) | 0.21% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attackers to inject arbitrary web script or HTML via the `redirect` parameter to (1)… | |
| Analizada | Media (6.9) | 0.50% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows… | |
| Analizada | Media (4.8) | 0.21% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected… | |
| Analizada | Media (4.8) | 0.21% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update 35 allow remote attackers… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allows remote attackers to inject arbitrary web script or HTML via… | |
| Analizada | Media (5.1) | 0.24% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, and 2023.Q3.5 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.7, and 7.4 update 50 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML… | |
| Analizada | Media (6.9) | 0.34% | — | Liferay Digital Experience PlatformLiferay Portal | 25/9/2025 | 17/6/2026 | A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to… | |
| Analizada | Media (5.3) | 0.18% | — | Liferay Digital Experience PlatformLiferay Portal | 24/9/2025 | 17/6/2026 | Una vulnerabilidad de Expiración de Sesión Insuficiente en Liferay Portal 7.4.3.121 hasta 7.3.3.131, y Liferay DXP 2024.Q4.0 hasta 2024.Q4.3, 2024.Q3.1 hasta 2024.Q3.13, 2024.Q2.0 hasta 2024.Q2.13, y 2024.Q1.1 hasta 2024.Q1.12 permite a un atacante remoto no autenticado reutilizar una sesión de usuario antigua… | |
| Analizada | Media (6.9) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 23/9/2025 | 25/9/2026 | Una vulnerabilidad de cross-site scripting (XSS) reflejada en Liferay Portal 7.4.0 hasta 7.4.3.112, y Liferay DXP 2024.Q1.1 hasta 2024.Q1.18 y 7.4 GA hasta la actualización 92 permite a un atacante remoto autenticado inyectar código JavaScript a través del parámetro… | |
| Analizada | Media (6.9) | 0.35% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a… | |
| Analizada | Media (5.3) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to add a note to an order in… | |
| Analizada | Media (5.3) | 0.25% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs. | |
| Analizada | Media (4.8) | 0.21% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected… | |
| Aplazada | Alta (7.1) | 0.38% | — | Sitecore Experience ManagerAISitecore Experience PlatformAI | 21/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cross-Site Scripting (XSS).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform… | |
| Analizada | Media (6.9) | 0.37% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote… | |
| Analizada | Media (5.1) | 0.18% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, and older unsupported versions allows remote attackers… | |
| Analizada | Media (6.9) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to… | |
| Analizada | Media (5.1) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 16/9/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter. | |
| Analizada | Media (6.9) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 16/9/2025 | 17/6/2026 | Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted… | |
| Analizada | Media (6.9) | 0.40% | — | Liferay Digital Experience PlatformLiferay Portal | 16/9/2025 | 17/6/2026 | Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to perform a… | |
| Analizada | Media (4.8) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 15/9/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7.4.3.51 through 7.4.3.109, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 update 51 through update 92, and 7.3 update 33 through update 35. allows remote attackers to inject arbitrary web script or… | |
| Analizada | Media (5.3) | 0.25% | — | Liferay Digital Experience PlatformLiferay Portal | 15/9/2025 | 17/6/2026 | In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions, the default membership type of a newly created site is “Open” which allows any registered users to become a member of the site. A remote… |