Vulnerability Name CVE Severity
Liferay DXP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26272) CVE-2024-26272
Liferay DXP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26273) CVE-2024-26273
Liferay DXP CVE-2021-38266 Vulnerability (CVE-2021-38266) CVE-2021-38266
Liferay DXP CVE-2024-25148 Vulnerability (CVE-2024-25148) CVE-2024-25148
Liferay DXP Deserialization of Untrusted Data Vulnerability (CVE-2020-15842) CVE-2020-15842
Liferay DXP Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-42123) CVE-2022-42123
Liferay DXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42121) CVE-2022-42121
Liferay DXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-33945) CVE-2023-33945
Liferay DXP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606) CVE-2024-25606
Liferay DXP Incorrect Authorization Vulnerability (CVE-2024-38002) CVE-2024-38002
Liferay DXP Inefficient Regular Expression Complexity Vulnerability (CVE-2022-42124) CVE-2022-42124
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949) CVE-2023-33949
Liferay DXP Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2024-25607) CVE-2024-25607
Liferay Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-13445) CVE-2020-13445
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2019-11444) CVE-2019-11444
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2020-28884) CVE-2020-28884
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2020-28885) CVE-2020-28885
Liferay JSON service API authentication vulnerability
Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-33323) CVE-2021-33323
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-33338) CVE-2021-33338
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-35030) CVE-2023-35030
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26271) CVE-2024-26271
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26272) CVE-2024-26272
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26273) CVE-2024-26273
Liferay Portal CVE-2020-15841 Vulnerability (CVE-2020-15841) CVE-2020-15841
Liferay Portal CVE-2021-38266 Vulnerability (CVE-2021-38266) CVE-2021-38266
Liferay Portal CVE-2024-25148 Vulnerability (CVE-2024-25148) CVE-2024-25148
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2019-16891) CVE-2019-16891
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-15842) CVE-2020-15842
Liferay Portal Improper Authentication Vulnerability (CVE-2021-29047) CVE-2021-29047
Liferay Portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-28981) CVE-2022-28981
Liferay Portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-42123) CVE-2022-42123
Liferay Portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-42125) CVE-2022-42125
Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-29053) CVE-2021-29053
Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42121) CVE-2022-42121
Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-33945) CVE-2023-33945
Liferay Portal Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606) CVE-2024-25606
Liferay Portal Incorrect Authorization Vulnerability (CVE-2021-33335) CVE-2021-33335
Liferay Portal Incorrect Authorization Vulnerability (CVE-2024-38002) CVE-2024-38002
Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2022-42124) CVE-2022-42124
Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2023-33950) CVE-2023-33950
Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949) CVE-2023-33949
Liferay Portal Insufficient Session Expiration Vulnerability (CVE-2021-33322) CVE-2021-33322
Liferay Portal Missing Authorization Vulnerability (CVE-2023-33948) CVE-2023-33948
Liferay Portal Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5327) CVE-2010-5327
Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-10795) CVE-2018-10795
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-24554) CVE-2020-24554
Liferay Portal Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2024-25607) CVE-2024-25607
Liferay Portal Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2021-33321) CVE-2021-33321
Liferay TunnelServlet Deserialization Remote Code Execution
Liferay version older than 7.0
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-4359) CVE-2008-4359
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-4360) CVE-2008-4360
Lighttpd Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-19052) CVE-2018-19052
Lighttpd Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2015-3200) CVE-2015-3200
Lighttpd Inadequate Encryption Strength Vulnerability (CVE-2013-4508) CVE-2013-4508
Lighttpd Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2022-41556) CVE-2022-41556
Lighttpd NULL Pointer Dereference Vulnerability (CVE-2022-37797) CVE-2022-37797
Lighttpd Other Vulnerability (CVE-2007-1870) CVE-2007-1870
Lighttpd Other Vulnerability (CVE-2007-3949) CVE-2007-3949
Lighttpd Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4559) CVE-2013-4559
Lighttpd Uncontrolled Resource Consumption Vulnerability (CVE-2022-30780) CVE-2022-30780
lighttpd v1.4.34 SQL injection and path traversal CVE-2014-2323 CVE-2014-2324
LimeSurvey CVE-2009-1604 Vulnerability (CVE-2009-1604) CVE-2009-1604
LimeSurvey Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-16177) CVE-2019-16177
LimeSurvey Improper Input Validation Vulnerability (CVE-2019-15640) CVE-2019-15640
LimeSurvey Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-1000659) CVE-2018-1000659
LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-4927) CVE-2012-4927
LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-5017) CVE-2014-5017
LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-43279) CVE-2022-43279
LimeSurvey Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-16174) CVE-2019-16174
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16185) CVE-2019-16185
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16186) CVE-2019-16186
LimeSurvey Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2019-16187) CVE-2019-16187
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-1000658) CVE-2018-1000658