Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.47% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject… | |
| Analizada | Media (6.1) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (6.1) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (6.1) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (6.1) | 0.62% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked… | |
| Analizada | Media (5.4) | 0.62% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via… | |
| Analizada | Media (6.1) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted… | |
| Analizada | Media (6.3) | 0.28% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's… | |
| Analizada | Media (5.3) | 0.44% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password. | |
| Analizada | Media (5.3) | 0.53% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the… | |
| Analizada | Media (5.3) | 0.53% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily… | |
| Analizada | Media (6.5) | 0.71% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote… | |
| Analizada | Media (5.4) | 0.52% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (6.1) | 0.36% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two forward slashes, which allows remote attackers to redirect users to… | |
| Analizada | Media (6.1) | 0.96% | 💥 Exploit | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to… | |
| Analizada | Alta (7.5) | 0.33% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack… | |
| Analizada | Alta (8.7) | 0.50% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume… | |
| Analizada | Media (5.3) | 0.48% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any… | |
| Analizada | Media (6.5) | 0.41% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission… | |
| Analizada | Media (4.3) | 0.44% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user's full name from the page's title by… | |
| Analizada | Media (5.4) | 0.33% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled, which allows remote… |