In Liferay Portal versions 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP versions 7.4.0 through 7.4.3.111, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 a medium severity vulnerability CVE-2025-62276 was detected. This vulnerability allows local users to access downloaded files via the browser’s cache due to an incorrect Cache-Control header configuration. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112 and Liferay DXP to version 2024.Q1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62276.
Read more CMSIn Liferay Portal versions 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP versions 7.4.0 through 7.4.3.111, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 a medium severity vulnerability CVE-2025-62275 was detected. This vulnerability allows remote attackers to view images in blog entries without proper authorization by exploiting a missing permission check via a crafted URL. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112 and Liferay DXP to version 2024.Q1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62275.
Read more CMSIn Liferay Portal versions 7.4.3.35 through 7.4.3.111 and Liferay DXP versions 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 U35 through U92 a medium severity vulnerability CVE-2025-62267 was detected. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML via crafted payloads in a user’s First Name, Middle Name, or Last Name fields, leading to multiple cross-site scripting (XSS) issues. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112 and Liferay DXP to version 2024.Q1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62267.
Read more CMSIn Nagios XI versions prior to 2024R1.1 a medium severity vulnerability CVE-2024-13992 was detected. This vulnerability allows remote attackers to execute arbitrary JavaScript in a victim’s browser via a crafted link that targets the “missing page” (404) page, due to improper validation or escaping of user-supplied input in `page-missing.php`. To address this issue, users should upgrade Nagios XI to version 2024R1.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13992.
Read more MonitoringIn Liferay Portal versions 7.4.3.8 through 7.4.3.111, and Liferay DXP versions 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, Liferay DXP 7.4 U4 through U92 a high severity vulnerability CVE-2025-62264 was detected. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML via the `_com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_selectedLanguageId` parameter, leading to a reflected cross-site scripting (XSS) issue. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112 and Liferay DXP to version 2024.Q1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62264.
Read more CMSIn Rancher Manager versions prior to 2.11.7 and 2.12.3 a medium severity vulnerability CVE-2023-32199 was detected. This issue allows users to retain administrative access to clusters even after a custom GlobalRole or its binding has been removed, provided the role included wildcard * permissions for resources or non-resource URLs. To fix this issue, users should upgrade to Rancher Manager versions 2.11.7 or 2.12.3 or later. For more details, visit https://avd.aquasec.com/nvd/2023/cve-2023-32199.
In Rancher Manager versions 2.9.0 through 2.12.2 a medium severity vulnerability CVE-2024-58269 was detected. This vulnerability allows sensitive information — including secret data, cluster import URLs, and registration tokens — to be exposed to any entity with access to Rancher audit logs. To fix this vulnerability, users should upgrade to version 2.12.3 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-58269.
Read more Developer ToolsIn Liferay Portal versions 7.4.0 through 7.4.3.119 and Liferay DXP versions 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions a medium severity vulnerability CVE-2025-62257 was detected. This vulnerability allows remote attackers to determine a user’s password through brute force attacks, even when account lockout protection is enabled. To fix this vulnerability, users should upgrade to Liferay Portal 7.4.3.120, Liferay DXP 2024.Q4.0, 2024.Q3.0, 2024.Q2.0, or 2024.Q1.6. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62257.
Read more CMSIn Liferay Portal versions 7.4.0 through 7.4.3.119 and older unsupported versions, and Liferay DXP versions 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions a medium severity vulnerability CVE‑2025‑62266 was detected. This vulnerability allows remote attackers to redirect users to arbitrary external URLs due to DNS rebinding attacks. To fix this vulnerability, users should upgrade to Liferay Portal 7.4.3.120, Liferay DXP 2024.Q4.0, 2024.Q3.0, 2024.Q2.0, or 2024.Q1.6. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62266.
Read more CMS