NDIx
11 записей с упоминанием · 1 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2026-59084Эксплойта нет | Apache Tomcat: EncryptInterceptor requirements not clearly documentedapache · tomcat · CWE-1059 | Критическая9,1 | — | 0,5 % | 14 июл. 2026 г. |
27Наблюдать | CVE-2025-43779Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Qliferay · digital experience platform · CWE-79 | Средняя6,9 | — | 0,2 % | 23 сент. 2025 г. |
18Наблюдать | CVE-2025-43776Эксплойта нет | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 202liferay · digital experience platform · CWE-209 | Средняя4,6 | — | 0,2 % | 9 сент. 2025 г. |
20Наблюдать | CVE-2025-43755Эксплойта нет | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 20liferay · digital experience platform · CWE-79 | Средняя5,1 | — | 0,2 % | 21 авг. 2025 г. |
19Наблюдать | CVE-2025-43757Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Qliferay · digital experience platform · CWE-79 | Средняя4,8 | — | 0,2 % | 20 авг. 2025 г. |
20Наблюдать | CVE-2025-43746Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Qliferay · digital experience platform · CWE-79 | Средняя5,1 | — | 0,2 % | 20 авг. 2025 г. |
20Наблюдать | CVE-2025-43744Эксплойта нет | A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 202liferay · digital experience platform · CWE-79 | Средняя5,1 | — | 0,2 % | 19 авг. 2025 г. |
27Наблюдать | CVE-2025-43745Эксплойта нет | A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2liferay · digital experience platform · CWE-352 | Средняя6,9 | — | 0,2 % | 19 авг. 2025 г. |
20Наблюдать | CVE-2025-43737Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Qliferay · digital experience platform · CWE-79 | Средняя5,1 | — | 0,3 % | 19 авг. 2025 г. |
20Наблюдать | CVE-2025-43738Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Qliferay · digital experience platform · CWE-79 | Средняя5,1 | — | 0,2 % | 19 авг. 2025 г. |
18Наблюдать | CVE-2025-43740Эксплойта нет | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, liferay · digital experience platform · CWE-79 | Средняя4,6 | — | 0,2 % | 19 авг. 2025 г. |
- CVE-2026-5908436Наблюдать
Apache Tomcat: EncryptInterceptor requirements not clearly documented
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %apache · tomcat14 июл. 2026 г.
- CVE-2025-4377927Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q
СредняяCVSS 6,9Эксплойта нетEPSS 0 %liferay · digital experience platform23 сент. 2025 г.
- CVE-2025-4377618Наблюдать
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 202
СредняяCVSS 4,6Эксплойта нетEPSS 0 %liferay · digital experience platform9 сент. 2025 г.
- CVE-2025-4375520Наблюдать
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 20
СредняяCVSS 5,1Эксплойта нетEPSS 0 %liferay · digital experience platform21 авг. 2025 г.
- CVE-2025-4375719Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q
СредняяCVSS 4,8Эксплойта нетEPSS 0 %liferay · digital experience platform20 авг. 2025 г.
- CVE-2025-4374620Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q
СредняяCVSS 5,1Эксплойта нетEPSS 0 %liferay · digital experience platform20 авг. 2025 г.
- CVE-2025-4374420Наблюдать
A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 202
СредняяCVSS 5,1Эксплойта нетEPSS 0 %liferay · digital experience platform19 авг. 2025 г.
- CVE-2025-4374527Наблюдать
A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2
СредняяCVSS 6,9Эксплойта нетEPSS 0 %liferay · digital experience platform19 авг. 2025 г.
- CVE-2025-4373720Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q
СредняяCVSS 5,1Эксплойта нетEPSS 0 %liferay · digital experience platform19 авг. 2025 г.
- CVE-2025-4373820Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q
СредняяCVSS 5,1Эксплойта нетEPSS 0 %liferay · digital experience platform19 авг. 2025 г.
- CVE-2025-4374018Наблюдать
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8,
СредняяCVSS 4,6Эксплойта нетEPSS 0 %liferay · digital experience platform19 авг. 2025 г.