Skip to content
Noroxi

NDIx

11 credited records · 1 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Apache Tomcat: EncryptInterceptor requirements not clearly documented

    CriticalCVSS 9.1No exploitEPSS 1%

    apache · tomcatJul 14, 2026

  • A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q

    MediumCVSS 6.9No exploitEPSS 0%

    liferay · digital experience platformSep 23, 2025

  • A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 202

    MediumCVSS 4.6No exploitEPSS 0%

    liferay · digital experience platformSep 9, 2025

  • A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 20

    MediumCVSS 5.1No exploitEPSS 0%

    liferay · digital experience platformAug 21, 2025

  • A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q

    MediumCVSS 4.8No exploitEPSS 0%

    liferay · digital experience platformAug 20, 2025

  • A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q

    MediumCVSS 5.1No exploitEPSS 0%

    liferay · digital experience platformAug 20, 2025

  • A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 202

    MediumCVSS 5.1No exploitEPSS 0%

    liferay · digital experience platformAug 19, 2025

  • A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2

    MediumCVSS 6.9No exploitEPSS 0%

    liferay · digital experience platformAug 19, 2025

  • A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q

    MediumCVSS 5.1No exploitEPSS 0%

    liferay · digital experience platformAug 19, 2025

  • A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q

    MediumCVSS 5.1No exploitEPSS 0%

    liferay · digital experience platformAug 19, 2025

  • A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8,

    MediumCVSS 4.6No exploitEPSS 0%

    liferay · digital experience platformAug 19, 2025