Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.38% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2)… | |
| Analizada | Media (5.4) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's… | |
| Analizada | Media (5.4) | 0.47% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject… | |
| Analizada | Media (6.1) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (6.1) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (6.1) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (6.1) | 0.62% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked… | |
| Analizada | Media (5.4) | 0.62% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via… | |
| Analizada | Media (6.1) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted… | |
| Aplazada | Alta (8.8) | 0.28% | — | Liferay DXPAILiferay PortalAI | 20/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 before fix pack 11 allows remote attackers to accept the site's terms of use via social engineering and enticing the user to visit a malicious page. | |
| Analizada | Media (6.3) | 0.28% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's… | |
| Analizada | Media (5.3) | 0.44% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password. | |
| Analizada | Media (5.3) | 0.53% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the… | |
| Analizada | Media (5.3) | 0.53% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily… | |
| Analizada | Media (6.5) | 0.71% | — | Liferay PortalLiferay Digital Experience Platform | 20/2/2024 | 17/6/2026 | The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote… | |
| Analizada | Media (5.4) | 0.52% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (6.1) | 0.36% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two forward slashes, which allows remote attackers to redirect users to… | |
| Analizada | Media (6.1) | 0.96% | 💥 Exploit | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to… | |
| Analizada | Alta (7.5) | 0.33% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack… | |
| Analizada | Alta (8.7) | 0.50% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume… | |
| Analizada | Media (5.3) | 0.48% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any… |