Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial Of Service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Prompt Leakage Llm Sensitive Information Disclosure Malware Missing Update Privilege Escalation SSRF Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Liferay DXP Uncontrolled Resource Consumption Vulnerability (CVE-2025-43796) CVE-2025-43796 CWE-400 CWE-400 High Liferay DXP Uncontrolled Resource Consumption Vulnerability (CVE-2025-62260) CVE-2025-62260 CWE-400 CWE-400 High Liferay DXP Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2024-25607) CVE-2024-25607 CWE-916 CWE-916 High Liferay Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-13445) CVE-2020-13445 CWE-138 CWE-138 High Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2019-11444) CVE-2019-11444 CWE-138 CWE-138 High Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2020-28884) CVE-2020-28884 CWE-138 CWE-138 High Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2020-28885) CVE-2020-28885 CWE-138 CWE-138 High Liferay JSON service API authentication vulnerability CWE-287 CWE-287 High Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2025-43790) CVE-2025-43790 CWE-639 CWE-639 High Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-33323) CVE-2021-33323 CWE-312 CWE-312 High Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-33338) CVE-2021-33338 CWE-352 CWE-352 High Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-35030) CVE-2023-35030 CWE-352 CWE-352 High Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26271) CVE-2024-26271 CWE-352 CWE-352 High Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26272) CVE-2024-26272 CWE-352 CWE-352 High Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26273) CVE-2024-26273 CWE-352 CWE-352 High Liferay Portal CVE-2020-15841 Vulnerability (CVE-2020-15841) CVE-2020-15841 High Liferay Portal CVE-2021-38266 Vulnerability (CVE-2021-38266) CVE-2021-38266 High Liferay Portal CVE-2024-25148 Vulnerability (CVE-2024-25148) CVE-2024-25148 High Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2019-16891) CVE-2019-16891 CWE-502 CWE-502 High Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-15842) CVE-2020-15842 CWE-502 CWE-502 High Liferay Portal Improper Authentication Vulnerability (CVE-2021-29047) CVE-2021-29047 CWE-287 CWE-287 High Liferay Portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-28981) CVE-2022-28981 CWE-22 CWE-22 High Liferay Portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-42123) CVE-2022-42123 CWE-22 CWE-22 High Liferay Portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-42125) CVE-2022-42125 CWE-22 CWE-22 High Liferay Portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2025-43813) CVE-2025-43813 CWE-22 CWE-22 High Liferay Portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2025-62254) CVE-2025-62254 CWE-22 CWE-22 High Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-29053) CVE-2021-29053 CWE-138 CWE-138 High Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42121) CVE-2022-42121 CWE-138 CWE-138 High Liferay Portal Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-33945) CVE-2023-33945 CWE-138 CWE-138 High Liferay Portal Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606) CVE-2024-25606 CWE-611 CWE-611 High Liferay Portal Improper Validation of Specified Quantity in Input Vulnerability (CVE-2025-43793) CVE-2025-43793 CWE-1284 CWE-1284 High Liferay Portal Incorrect Authorization Vulnerability (CVE-2021-33335) CVE-2021-33335 CWE-863 CWE-863 High Liferay Portal Incorrect Authorization Vulnerability (CVE-2024-38002) CVE-2024-38002 CWE-863 CWE-863 High Liferay Portal Incorrect Authorization Vulnerability (CVE-2025-3586) CVE-2025-3586 CWE-863 CWE-863 High Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2022-42124) CVE-2022-42124 CWE-1333 CWE-1333 High Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2023-33950) CVE-2023-33950 CWE-1333 CWE-1333 High Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949) CVE-2023-33949 CWE-1188 CWE-1188 High Liferay Portal Insertion of Sensitive Information Into Sent Data Vulnerability (CVE-2025-43768) CVE-2025-43768 CWE-201 CWE-201 High Liferay Portal Insufficient Session Expiration Vulnerability (CVE-2021-33322) CVE-2021-33322 CWE-613 CWE-613 High Liferay Portal Missing Authorization Vulnerability (CVE-2023-33948) CVE-2023-33948 CWE-862 CWE-862 High Liferay Portal Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2025-43816) CVE-2025-43816 CWE-401 CWE-401 High Liferay Portal Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5327) CVE-2010-5327 CWE-264 CWE-264 High Liferay Portal Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-4581) CVE-2025-4581 CWE-918 CWE-918 High Liferay Portal Unchecked Input for Loop Condition Vulnerability (CVE-2025-43801) CVE-2025-43801 CWE-606 CWE-606 High Liferay Portal Uncontrolled Resource Consumption Vulnerability (CVE-2025-43796) CVE-2025-43796 CWE-400 CWE-400 High Liferay Portal Uncontrolled Resource Consumption Vulnerability (CVE-2025-62260) CVE-2025-62260 CWE-400 CWE-400 High Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-10795) CVE-2018-10795 CWE-434 CWE-434 High Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-24554) CVE-2020-24554 CWE-601 CWE-601 High Liferay Portal Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2024-25607) CVE-2024-25607 CWE-916 CWE-916 High Liferay Portal Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2021-33321) CVE-2021-33321 CWE-640 CWE-640 High Liferay TunnelServlet Deserialization Remote Code Execution CWE-502 CWE-502 High Liferay version older than 7.0 CWE-502 CWE-502 High Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-4359) CVE-2008-4359 CWE-200 CWE-200 High Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-4360) CVE-2008-4360 CWE-200 CWE-200 High Lighttpd Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-19052) CVE-2018-19052 CWE-22 CWE-22 High Lighttpd Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2015-3200) CVE-2015-3200 CWE-138 CWE-138 High Lighttpd Inadequate Encryption Strength Vulnerability (CVE-2013-4508) CVE-2013-4508 CWE-326 CWE-326 High Lighttpd Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2022-41556) CVE-2022-41556 CWE-401 CWE-401 High Lighttpd NULL Pointer Dereference Vulnerability (CVE-2022-37797) CVE-2022-37797 CWE-476 CWE-476 High Lighttpd Other Vulnerability (CVE-2007-1870) CVE-2007-1870 High Lighttpd Other Vulnerability (CVE-2007-3949) CVE-2007-3949 High Lighttpd Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4559) CVE-2013-4559 CWE-264 CWE-264 High Lighttpd Uncontrolled Resource Consumption Vulnerability (CVE-2022-30780) CVE-2022-30780 CWE-400 CWE-400 High lighttpd v1.4.34 SQL injection and path traversal CVE-2014-2323 CVE-2014-2324 CWE-89 CWE-89 High LimeSurvey Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-39063) CVE-2024-39063 CWE-352 CWE-352 High LimeSurvey CVE-2009-1604 Vulnerability (CVE-2009-1604) CVE-2009-1604 High LimeSurvey Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-16177) CVE-2019-16177 CWE-200 CWE-200 High LimeSurvey Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-42902) CVE-2024-42902 CWE-94 CWE-94 High LimeSurvey Improper Input Validation Vulnerability (CVE-2019-15640) CVE-2019-15640 CWE-20 CWE-20 High LimeSurvey Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-1000659) CVE-2018-1000659 CWE-22 CWE-22 High LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-4927) CVE-2012-4927 CWE-138 CWE-138 High LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-5017) CVE-2014-5017 CWE-138 CWE-138 High LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-43279) CVE-2022-43279 CWE-138 CWE-138 High LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2025-56421) CVE-2025-56421 CWE-138 CWE-138 High LimeSurvey Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-16174) CVE-2019-16174 CWE-611 CWE-611 High 1...27282930...177 28 / 177