Перейти к содержимому
Noroxi

foobar7

33 записей с упоминанием · 20 за 12 месяцев · 0 в CISA KEV

Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.

Записи с упоминанием

Исследователи
  • CVE-2025-62265
    19Наблюдать

    Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform30 окт. 2025 г.

  • CVE-2025-62252
    21Наблюдать

    Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    liferay · digital experience platform13 окт. 2025 г.

  • CVE-2025-62246
    19Наблюдать

    Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Li

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform13 окт. 2025 г.

  • CVE-2025-62242
    21Наблюдать

    Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 20

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    liferay · digital experience platform13 окт. 2025 г.

  • CVE-2025-62241
    21Наблюдать

    Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authe

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    liferay · digital experience platform13 окт. 2025 г.

  • CVE-2025-62243
    21Наблюдать

    Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 t

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    liferay · digital experience platform13 окт. 2025 г.

  • CVE-2025-62244
    19Наблюдать

    Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 t

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform13 окт. 2025 г.

  • CVE-2025-62245
    20Наблюдать

    Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    liferay · digital experience platform10 окт. 2025 г.

  • CVE-2025-62239
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    liferay · digital experience platform10 окт. 2025 г.

  • CVE-2025-62238
    19Наблюдать

    Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform10 окт. 2025 г.

  • CVE-2025-62237
    19Наблюдать

    Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform10 окт. 2025 г.

  • CVE-2025-62240
    19Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform9 окт. 2025 г.

  • CVE-2025-43771
    19Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay D

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform8 окт. 2025 г.

  • CVE-2025-43830
    20Наблюдать

    Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    liferay · digital experience platform8 окт. 2025 г.

  • CVE-2025-43829
    19Наблюдать

    Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Lifer

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform8 окт. 2025 г.

  • CVE-2025-43821
    19Наблюдать

    Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Life

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform8 окт. 2025 г.

  • CVE-2025-43822
    19Наблюдать

    Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform7 окт. 2025 г.

  • CVE-2025-43823
    19Наблюдать

    Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 202

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform7 окт. 2025 г.

  • CVE-2025-43824
    19Наблюдать

    The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform6 окт. 2025 г.

  • CVE-2025-43827
    21Наблюдать

    Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported ver

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    liferay · digital experience platform30 сент. 2025 г.

  • CVE-2025-43820
    19Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 through

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform29 сент. 2025 г.

  • CVE-2025-43818
    19Наблюдать

    Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 thro

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform29 сент. 2025 г.

  • CVE-2025-43811
    19Наблюдать

    Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Lif

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform29 сент. 2025 г.

  • CVE-2025-43810
    21Наблюдать

    Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    liferay · digital experience platform22 сент. 2025 г.

  • CVE-2025-43807
    19Наблюдать

    Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    liferay · digital experience platform22 сент. 2025 г.