Adobe

Coldfusion

208 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.81%
  • Veröffentlicht 13.05.2025 20:49:25
  • Zuletzt bearbeitet 19.05.2025 20:35:36

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnera...

  • EPSS 0.74%
  • Veröffentlicht 08.04.2025 20:15:27
  • Zuletzt bearbeitet 14.04.2025 15:57:32

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may ...

  • EPSS 1.17%
  • Veröffentlicht 08.04.2025 20:15:27
  • Zuletzt bearbeitet 21.04.2025 18:39:13

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protec...

  • EPSS 1.83%
  • Veröffentlicht 08.04.2025 20:15:27
  • Zuletzt bearbeitet 23.04.2025 16:44:53

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protec...

  • EPSS 0.07%
  • Veröffentlicht 08.04.2025 20:15:26
  • Zuletzt bearbeitet 21.04.2025 18:37:56

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leve...

  • EPSS 0.08%
  • Veröffentlicht 08.04.2025 20:15:26
  • Zuletzt bearbeitet 21.04.2025 18:33:41

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass ...

  • EPSS 0.07%
  • Veröffentlicht 08.04.2025 20:15:26
  • Zuletzt bearbeitet 24.04.2025 17:23:25

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A low pri...

  • EPSS 0.83%
  • Veröffentlicht 08.04.2025 20:15:26
  • Zuletzt bearbeitet 12.05.2025 16:40:28

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could ex...

Medienbericht
  • EPSS 7.3%
  • Veröffentlicht 08.04.2025 20:15:25
  • Zuletzt bearbeitet 15.07.2025 18:40:24

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitiv...

Medienbericht
  • EPSS 1.63%
  • Veröffentlicht 08.04.2025 20:15:25
  • Zuletzt bearbeitet 23.04.2025 16:45:08

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnera...