Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
2016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.26% | — | Liferay Digital Experience PlatformLiferay Portal | 15/9/2025 | 17/6/2026 | Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, which allows remote users… | |
| Analizada | Baja (2.1) | 0.18% | — | Liferay Digital Experience Platform | 15/9/2025 | 17/6/2026 | Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user. | |
| Analizada | Media (4.8) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 15/9/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an object with a rich text type field. | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 15/9/2025 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a "Rich Text"… | |
| Analizada | Baja (2.3) | 0.32% | — | Liferay Digital Experience PlatformLiferay Portal | 15/9/2025 | 17/6/2026 | Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly obtain the remote address of the live site from the database which,… | |
| Analizada | Media (6.9) | 0.40% | — | Liferay Digital Experience PlatformLiferay Portal | 15/9/2025 | 17/6/2026 | Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote… | |
| Analizada | Media (4.6) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 15/9/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote authenticated attackers with the instance… | |
| Analizada | Alta (7.1) | 0.38% | — | Liferay Digital Experience PlatformLiferay Portal | 12/9/2025 | 17/6/2026 | Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing… | |
| Analizada | Media (5.1) | 0.24% | — | Liferay Digital Experience PlatformLiferay Portal | 12/9/2025 | 17/6/2026 | Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the… | |
| Analizada | Media (5.1) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 12/9/2025 | 17/6/2026 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote… | |
| Analizada | Baja (1) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 12/9/2025 | 17/6/2026 | JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered and invoked directly as classes which allows Service Access Policies get executed. | |
| Analizada | Media (5.3) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 12/9/2025 | 17/6/2026 | The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations. | |
| Analizada | Alta (7.4) | 0.34% | — | Liferay Digital Experience PlatformLiferay Portal | 11/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.6, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to access, create, edit, relate data/object… | |
| Analizada | Media (5.3) | 0.33% | — | Liferay Digital Experience PlatformLiferay Portal | 11/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.7, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote authenticated users to access a workflow definition by name via the API | |
| Analizada | Media (5.1) | 0.24% | — | Liferay Digital Experience PlatformLiferay Portal | 10/9/2025 | 25/9/2026 | Vulnerabilidad de cross-site scripting (XSS) reflejada en Liferay Portal 7.4.3.73 hasta 7.4.3.128, y Liferay DXP 2024.Q3.0 hasta 2024.Q3.1, 2024.Q2.0 hasta 2024.Q2.13, 2024.Q1.1 hasta 2024.Q1.12, 7.4 actualización 73 hasta actualización 92 permite a atacantes remotos inyectar script web o HTML arbitrario a través de… | |
| Analizada | Media (6.2) | 0.26% | — | Liferay Digital Experience PlatformLiferay Portal | 10/9/2025 | 25/9/2026 | Vulnerabilidad de control de acceso inadecuado en Liferay Portal 7.4.0 hasta 7.4.3.124, y Liferay DXP 2024.Q2.0 hasta 2024.Q2.8, 2024.Q1.1 hasta 2024.Q1.12 y 7.4 GA hasta la actualización 92 permite a los usuarios invitados obtener información de entradas de objetos a través del API Builder. | |
| Analizada | Media (4.6) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 10/9/2025 | 25/9/2026 | Vulnerabilidad de cross-site scripting (XSS) almacenado en Liferay Portal 7.4.3.45 hasta 7.4.3.128, y Liferay DXP 2024 Q2.0 hasta 2024.Q2.9, 2024.Q1.1 hasta 2024.Q1.12, y 7.4 actualización 45 hasta actualización 92 permite a atacantes remotos ejecutar un script web o HTML arbitrario en la página My Workflow Tasks. | |
| Analizada | Media (6.9) | 0.31% | — | Liferay Digital Experience PlatformLiferay Portal | 9/9/2025 | 17/6/2026 | Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response. | |
| Analizada | Media (5.3) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 9/9/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.12 allows remote attackers to inject arbitrary web script or HTML via the URL in search bar portlet | |
| Analizada | Media (4.6) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 9/9/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via remote app title field. | |
| Analizada | Media (5.4) | 5.3% | — | Adobe Experience Manager | 9/9/2025 | 17/6/2026 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This could result in bypassing security features within the application. Exploitation of… | |
| Analizada | Media (4.3) | 1.8% | 💥 Exploit | Adobe Experience Manager | 9/9/2025 | 17/6/2026 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access. | |
| Analizada | Media (4.9) | 0.43% | — | Adobe Experience Manager | 9/9/2025 | 17/6/2026 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. | |
| Analizada | Alta (7.7) | 5.8% | — | Adobe Experience Manager | 9/9/2025 | 17/6/2026 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Scope is changed | |
| Analizada | Media (6.5) | 0.48% | — | Adobe Experience Manager | 9/9/2025 | 17/6/2026 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. |