Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Arbitrary File Creation Authentication Bypass Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities Ldap Injection Malware Missing Update Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44309) CVE-2023-44309 CWE-707 CWE-707 Medium Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44310) CVE-2023-44310 CWE-707 CWE-707 Medium Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44311) CVE-2023-44311 CWE-707 CWE-707 Medium Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-47797) CVE-2023-47797 CWE-707 CWE-707 Medium Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25145) CVE-2024-25145 CWE-707 CWE-707 Medium Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-29053) CVE-2021-29053 CWE-138 CWE-138 High Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42120) CVE-2022-42120 CWE-138 CWE-138 Critical Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42121) CVE-2022-42121 CWE-138 CWE-138 High Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42122) CVE-2022-42122 CWE-138 CWE-138 Critical Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-33945) CVE-2023-33945 CWE-138 CWE-138 High Liferay Portal Incorrect Authorization Vulnerability (CVE-2021-33335) CVE-2021-33335 CWE-863 CWE-863 High Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-29052) CVE-2021-29052 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33324) CVE-2021-33324 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33327) CVE-2021-33327 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33333) CVE-2021-33333 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33334) CVE-2021-33334 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-38268) CVE-2021-38268 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-26595) CVE-2022-26595 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-41414) CVE-2022-41414 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-42127) CVE-2022-42127 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-42128) CVE-2022-42128 CWE-276 CWE-276 Medium Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-42130) CVE-2022-42130 CWE-276 CWE-276 Medium Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2022-42124) CVE-2022-42124 CWE-1333 CWE-1333 High Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2023-33950) CVE-2023-33950 CWE-1333 CWE-1333 High Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949) CVE-2023-33949 CWE-1188 CWE-1188 High Liferay Portal Insufficiently Protected Credentials Vulnerability (CVE-2021-29043) CVE-2021-29043 CWE-522 CWE-522 Medium Liferay Portal Insufficient Session Expiration Vulnerability (CVE-2021-33322) CVE-2021-33322 CWE-613 CWE-613 High Liferay Portal Missing Authorization Vulnerability (CVE-2022-38512) CVE-2022-38512 CWE-862 CWE-862 Medium Liferay Portal Missing Authorization Vulnerability (CVE-2022-39975) CVE-2022-39975 CWE-862 CWE-862 Medium Liferay Portal Missing Authorization Vulnerability (CVE-2023-3426) CVE-2023-3426 CWE-862 CWE-862 Medium Liferay Portal Missing Authorization Vulnerability (CVE-2023-33948) CVE-2023-33948 CWE-862 CWE-862 High Liferay Portal Observable Discrepancy Vulnerability (CVE-2024-25146) CVE-2024-25146 CWE-203 CWE-203 Medium Liferay Portal Origin Validation Error Vulnerability (CVE-2022-25146) CVE-2022-25146 CWE-346 CWE-346 Medium Liferay Portal Other Vulnerability (CVE-2023-33946) CVE-2023-33946 Medium Liferay Portal Other Vulnerability (CVE-2023-33947) CVE-2023-33947 Medium Liferay Portal Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5327) CVE-2010-5327 CWE-264 CWE-264 High Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-10795) CVE-2018-10795 CWE-434 CWE-434 High Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-15839) CVE-2020-15839 CWE-434 CWE-434 Medium Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-24554) CVE-2020-24554 CWE-601 CWE-601 High Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-33331) CVE-2021-33331 CWE-601 CWE-601 Medium Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977) CVE-2022-28977 CWE-601 CWE-601 Medium Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-35029) CVE-2023-35029 CWE-601 CWE-601 Medium Liferay Portal Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2021-33321) CVE-2021-33321 CWE-640 CWE-640 High Liferay TunnelServlet Deserialization Remote Code Execution CWE-502 CWE-502 High Liferay version older than 7.0 CWE-502 CWE-502 High Liferay version older than 7.1 CWE-918 CWE-918 Medium Liferay XMLRPC Blind SSRF CWE-918 CWE-918 Medium lightbox2 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9441) CVE-2014-9441 CWE-352 CWE-352 Medium Lighttpd Cryptographic Issues Vulnerability (CVE-2013-1427) CVE-2013-1427 Low Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1111) CVE-2008-1111 CWE-200 CWE-200 Medium Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1270) CVE-2008-1270 CWE-200 CWE-200 Medium Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-4359) CVE-2008-4359 CWE-200 CWE-200 High Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-4360) CVE-2008-4360 CWE-200 CWE-200 High Lighttpd Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-2324) CVE-2014-2324 CWE-22 CWE-22 Medium Lighttpd Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-19052) CVE-2018-19052 CWE-22 CWE-22 High Lighttpd Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2015-3200) CVE-2015-3200 CWE-138 CWE-138 High Lighttpd Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-2323) CVE-2014-2323 CWE-138 CWE-138 Critical Lighttpd Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2007-4727) CVE-2007-4727 CWE-119 CWE-119 Medium Lighttpd Inadequate Encryption Strength Vulnerability (CVE-2013-4508) CVE-2013-4508 CWE-326 CWE-326 High Lighttpd Integer Overflow or Wraparound Vulnerability (CVE-2019-11072) CVE-2019-11072 CWE-190 CWE-190 Critical Lighttpd Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2022-41556) CVE-2022-41556 CWE-401 CWE-401 High Lighttpd NULL Pointer Dereference Vulnerability (CVE-2022-37797) CVE-2022-37797 CWE-476 CWE-476 High Lighttpd Other Vulnerability (CVE-2005-0453) CVE-2005-0453 Medium Lighttpd Other Vulnerability (CVE-2006-0760) CVE-2006-0760 Low Lighttpd Other Vulnerability (CVE-2006-0814) CVE-2006-0814 Medium Lighttpd Other Vulnerability (CVE-2007-1869) CVE-2007-1869 Medium Lighttpd Other Vulnerability (CVE-2007-1870) CVE-2007-1870 High Lighttpd Other Vulnerability (CVE-2007-3946) CVE-2007-3946 Medium Lighttpd Other Vulnerability (CVE-2007-3947) CVE-2007-3947 Medium Lighttpd Other Vulnerability (CVE-2007-3948) CVE-2007-3948 Medium Lighttpd Other Vulnerability (CVE-2007-3949) CVE-2007-3949 High Lighttpd Other Vulnerability (CVE-2007-3950) CVE-2007-3950 Medium Lighttpd Other Vulnerability (CVE-2008-1531) CVE-2008-1531 Medium Lighttpd Other Vulnerability (CVE-2011-4362) CVE-2011-4362 Medium Lighttpd Out-of-bounds Write Vulnerability (CVE-2022-22707) CVE-2022-22707 CWE-787 CWE-787 Medium 1...62636465...293 63 / 293