Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-29053 |
|
SQL Injection in sqli (CVE-2021-29053)
SQL injection in sqli (CVE-2021-29053). Successful exploitation can lead to full system takeover.
|
| CVE-2021-29045 |
|
Cross-Site Scripting (XSS) in liferay (CVE-2021-29045)
cross-site scripting in liferay (CVE-2021-29045). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-29046 |
|
Cross-Site Scripting (XSS) in liferay (CVE-2021-29046)
cross-site scripting in liferay (CVE-2021-29046). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-29044 |
|
Cross-Site Scripting (XSS) in liferay (CVE-2021-29044)
cross-site scripting in liferay (CVE-2021-29044). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-29047 |
|
Authentication Bypass in liferay (CVE-2021-29047)
authentication bypass in liferay (CVE-2021-29047). Data can be tampered with by attackers.
|
| CVE-2021-29040 |
|
Vulnerability in liferay (CVE-2021-29040)
vulnerability in liferay (CVE-2021-29040). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-29041 |
|
Vulnerability in dos (CVE-2021-29041)
vulnerability in dos (CVE-2021-29041). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-29039 |
|
Cross-Site Scripting (XSS) in liferay (CVE-2021-29039)
cross-site scripting in liferay (CVE-2021-29039). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17868 |
|
Cross-Site Scripting (XSS) in liferay (CVE-2017-17868)
cross-site scripting in liferay (CVE-2017-17868). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12649 |
|
Cross-Site Scripting (XSS) in liferay (CVE-2017-12649)
cross-site scripting in liferay (CVE-2017-12649). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12648 |
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
|
| CVE-2017-12647 |
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
|
| CVE-2017-12646 |
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
|
| CVE-2017-12645 |
|
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
|
| CVE-2016-10404 |
|
Cross-Site Scripting (XSS) in liferay (CVE-2016-10404)
cross-site scripting in liferay (CVE-2016-10404). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-6517 |
|
Path Traversal in path-traversal (CVE-2016-6517)
path traversal in path-traversal (CVE-2016-6517). Successful exploitation can lead to full system takeover.
|
| CVE-2010-5327 |
|
Vulnerability in liferay (CVE-2010-5327)
vulnerability in liferay (CVE-2010-5327). Successful exploitation can lead to full system takeover.
|