|
194511
|
8.8 |
HIGH
Network
|
liferay
|
dxp liferay_portal
|
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter …
|
CWE-89
SQL Injection
|
CVE-2021-29053
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194512
|
6.1 |
MEDIUM
Network
|
liferay
|
dxp liferay_portal
|
Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29046
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194513
|
6.1 |
MEDIUM
Network
|
liferay
|
dxp liferay_portal
|
Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2021-29045
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194514
|
6.1 |
MEDIUM
Network
|
liferay
|
dxp liferay_portal
|
Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pac…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29044
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194515
|
5.9 |
MEDIUM
Network
|
liferay
|
dxp liferay_portal
|
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-29043
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194516
|
7.5 |
HIGH
Network
|
liferay
|
liferay_portal dxp
|
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly…
|
CWE-287
Improper Authentication
|
CVE-2021-29047
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194517
|
6.5 |
MEDIUM
Network
|
liferay
|
dxp
|
Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (…
|
NVD-CWE-noinfo
|
CVE-2021-29041
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194518
|
5.3 |
MEDIUM
Network
|
liferay
|
dxp liferay_portal
|
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which a…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-29040
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194519
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
|
CWE-79
Cross-site Scripting
|
CVE-2021-29039
|
2024-11-21 15:00 |
2021-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194520
|
9.8 |
CRITICAL
Network
|
qnap
|
hybrid_backup_sync
|
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This i…
|
NVD-CWE-Other
|
CVE-2021-28799
|
2024-11-21 15:00 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|