Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2025
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaScrip in the _com_liferay_users_admin_web_portlet_UsersAdminPortlet_assetTagNames parameter
CVSS Score
5.1
EPSS Score
0.0
Published
2025-08-20
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript in web content for friendly urls.
CVSS Score
6.9
EPSS Score
0.0
Published
2025-08-20
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
CVSS Score
7.5
EPSS Score
0.0
Published
2025-08-20
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
CVSS Score
5.5
EPSS Score
0.0
Published
2025-08-20
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
CVSS Score
4.3
EPSS Score
0.0
Published
2025-08-20
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
CVSS Score
4.7
EPSS Score
0.0
Published
2025-08-20
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
CVSS Score
6.5
EPSS Score
0.0
Published
2025-08-20
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
CVSS Score
6.5
EPSS Score
0.0
Published
2025-08-20
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
CVSS Score
5.2
EPSS Score
0.0
Published
2025-08-20
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
CVSS Score
8.7
EPSS Score
0.001
Published
2025-08-20


Contact Us

Shodan ® - All rights reserved