foobar7
33 записей с упоминанием · 20 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
19Наблюдать | CVE-2025-62265Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and liferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 30 окт. 2025 г. |
21Наблюдать | CVE-2025-62252Эксплойта нет | Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferayliferay · digital experience platform · CWE-639 | Средняя5,3 | — | 0,3 % | 13 окт. 2025 г. |
19Наблюдать | CVE-2025-62246Эксплойта нет | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 13 окт. 2025 г. |
21Наблюдать | CVE-2025-62242Эксплойта нет | Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 20liferay · digital experience platform · CWE-639 | Средняя5,3 | — | 0,3 % | 13 окт. 2025 г. |
21Наблюдать | CVE-2025-62241Эксплойта нет | Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote autheliferay · digital experience platform · CWE-639 | Средняя5,3 | — | 0,3 % | 13 окт. 2025 г. |
21Наблюдать | CVE-2025-62243Эксплойта нет | Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 tliferay · digital experience platform · CWE-863 | Средняя5,3 | — | 0,2 % | 13 окт. 2025 г. |
19Наблюдать | CVE-2025-62244Эксплойта нет | Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 tliferay · digital experience platform · CWE-639 | Средняя4,8 | — | 0,3 % | 13 окт. 2025 г. |
20Наблюдать | CVE-2025-62245Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023liferay · digital experience platform · CWE-352 | Средняя5,1 | — | 0,2 % | 10 окт. 2025 г. |
18Наблюдать | CVE-2025-62239Эксплойта нет | Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0liferay · digital experience platform · CWE-79 | Средняя4,6 | — | 0,2 % | 10 окт. 2025 г. |
19Наблюдать | CVE-2025-62238Эксплойта нет | Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, andliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 10 окт. 2025 г. |
19Наблюдать | CVE-2025-62237Эксплойта нет | Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2liferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 10 окт. 2025 г. |
19Наблюдать | CVE-2025-62240Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.liferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 9 окт. 2025 г. |
19Наблюдать | CVE-2025-43771Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay Dliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 8 окт. 2025 г. |
20Наблюдать | CVE-2025-43830Эксплойта нет | Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Qliferay · digital experience platform · CWE-79 | Средняя5,1 | — | 0,2 % | 8 окт. 2025 г. |
19Наблюдать | CVE-2025-43829Эксплойта нет | Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 8 окт. 2025 г. |
19Наблюдать | CVE-2025-43821Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Lifeliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 8 окт. 2025 г. |
19Наблюдать | CVE-2025-43822Эксплойта нет | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2liferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 7 окт. 2025 г. |
19Наблюдать | CVE-2025-43823Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 202liferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 7 окт. 2025 г. |
19Наблюдать | CVE-2025-43824Эксплойта нет | The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2liferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 6 окт. 2025 г. |
21Наблюдать | CVE-2025-43827Эксплойта нет | Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported verliferay · digital experience platform · CWE-639 | Средняя5,3 | — | 0,3 % | 30 сент. 2025 г. |
19Наблюдать | CVE-2025-43820Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 throughliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 29 сент. 2025 г. |
19Наблюдать | CVE-2025-43818Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 throliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 29 сент. 2025 г. |
19Наблюдать | CVE-2025-43811Эксплойта нет | Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Lifliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 29 сент. 2025 г. |
21Наблюдать | CVE-2025-43810Эксплойта нет | Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2liferay · digital experience platform · CWE-639 | Средняя5,3 | — | 0,3 % | 22 сент. 2025 г. |
19Наблюдать | CVE-2025-43807Эксплойта нет | Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.liferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 22 сент. 2025 г. |
- CVE-2025-6226519Наблюдать
Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform30 окт. 2025 г.
- CVE-2025-6225221Наблюдать
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay
СредняяCVSS 5,3Эксплойта нетEPSS 0 %liferay · digital experience platform13 окт. 2025 г.
- CVE-2025-6224619Наблюдать
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Li
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform13 окт. 2025 г.
- CVE-2025-6224221Наблюдать
Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 20
СредняяCVSS 5,3Эксплойта нетEPSS 0 %liferay · digital experience platform13 окт. 2025 г.
- CVE-2025-6224121Наблюдать
Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authe
СредняяCVSS 5,3Эксплойта нетEPSS 0 %liferay · digital experience platform13 окт. 2025 г.
- CVE-2025-6224321Наблюдать
Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 t
СредняяCVSS 5,3Эксплойта нетEPSS 0 %liferay · digital experience platform13 окт. 2025 г.
- CVE-2025-6224419Наблюдать
Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 t
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform13 окт. 2025 г.
- CVE-2025-6224520Наблюдать
Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023
СредняяCVSS 5,1Эксплойта нетEPSS 0 %liferay · digital experience platform10 окт. 2025 г.
- CVE-2025-6223918Наблюдать
Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0
СредняяCVSS 4,6Эксплойта нетEPSS 0 %liferay · digital experience platform10 окт. 2025 г.
- CVE-2025-6223819Наблюдать
Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform10 окт. 2025 г.
- CVE-2025-6223719Наблюдать
Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform10 окт. 2025 г.
- CVE-2025-6224019Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform9 окт. 2025 г.
- CVE-2025-4377119Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay D
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform8 окт. 2025 г.
- CVE-2025-4383020Наблюдать
Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q
СредняяCVSS 5,1Эксплойта нетEPSS 0 %liferay · digital experience platform8 окт. 2025 г.
- CVE-2025-4382919Наблюдать
Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Lifer
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform8 окт. 2025 г.
- CVE-2025-4382119Наблюдать
Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Life
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform8 окт. 2025 г.
- CVE-2025-4382219Наблюдать
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform7 окт. 2025 г.
- CVE-2025-4382319Наблюдать
Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 202
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform7 окт. 2025 г.
- CVE-2025-4382419Наблюдать
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform6 окт. 2025 г.
- CVE-2025-4382721Наблюдать
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported ver
СредняяCVSS 5,3Эксплойта нетEPSS 0 %liferay · digital experience platform30 сент. 2025 г.
- CVE-2025-4382019Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 through
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform29 сент. 2025 г.
- CVE-2025-4381819Наблюдать
Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 thro
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform29 сент. 2025 г.
- CVE-2025-4381119Наблюдать
Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Lif
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform29 сент. 2025 г.
- CVE-2025-4381021Наблюдать
Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2
СредняяCVSS 5,3Эксплойта нетEPSS 0 %liferay · digital experience platform22 сент. 2025 г.
- CVE-2025-4380719Наблюдать
Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform22 сент. 2025 г.