Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
297 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 17/4/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through… | |
| Analizada | Media (5.1) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 20/3/2025 | 17/6/2026 | The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 allows an unauthorized user to obtain entry data from forms. | |
| Analizada | Media (5.1) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 19/3/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module's… | |
| Aplazada | Media (5.3) | 65% | 💥 Exploit | Sitecore Experience ManagerAISitecore Experience PlatformAI | 20/2/2025 | 17/6/2026 | Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization. | |
| Analizada | Media (4.8) | 0.28% | — | Liferay PortalLiferay Digital Experience Platform | 17/12/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into… | |
| Modificada | Media (4.6) | 0.34% | — | Liferay PortalLiferay Digital Experience Platform | 17/12/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field | |
| Analizada | Media (6.1) | 0.24% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against… | |
| Modificada | Alta (8.8) | 0.65% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to… | |
| Analizada | Alta (8.8) | 0.38% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut… | |
| Analizada | Alta (8.8) | 0.38% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the… | |
| Analizada | Alta (8.8) | 0.38% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2)… | |
| Analizada | Alta (7.5) | 47% | 💥 Exploit | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience Platform | 15/9/2024 | 17/6/2026 | An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files. | |
| Analizada | Media (5.4) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's… | |
| Analizada | Media (5.4) | 0.47% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject… | |
| Analizada | Media (6.1) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (6.1) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (6.1) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (6.1) | 0.62% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked… | |
| Analizada | Media (5.4) | 0.62% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via… | |
| Analizada | Media (6.1) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted… | |
| Analizada | Media (6.3) | 0.28% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's… |