NA - CVE-2023-5190 - Open redirect vulnerability in the Countries...
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows...
NA - CVE-2023-44308 - Open redirect vulnerability in adaptive media...
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external...
NA - CVE-2024-22234 - In Spring Security, versions 6.1.x prior to...
In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the...
NA - CVE-2024-25149 - Liferay Portal 7.2.0 through 7.4.1, and older...
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict...
NA - CVE-2024-25150 - Information disclosure vulnerability in the...
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and...
NA - CVE-2024-25973 - The Frentix GmbH OpenOlat LMS is affected by...
The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a name that...
NA - CVE-2024-25974 - The Frentix GmbH OpenOlat LMS is affected by...
The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an...
NA - CVE-2024-1608 - In OPPO Usercenter Credit SDK, there's a...
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
NA - CVE-2024-25604 - Liferay Portal 7.2.0 through 7.4.3.4, and older...
Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly...
NA - CVE-2024-25605 - The Journal module in Liferay Portal 7.2.0...
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions...