CVE-2025-27190
- EPSS 0.12%
- Veröffentlicht 08.04.2025 20:17:12
- Zuletzt bearbeitet 23.06.2025 19:30:03
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass...
CVE-2025-27191
- EPSS 0.12%
- Veröffentlicht 08.04.2025 20:17:11
- Zuletzt bearbeitet 20.05.2025 14:30:41
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass...
CVE-2025-27192
- EPSS 0.08%
- Veröffentlicht 08.04.2025 20:17:10
- Zuletzt bearbeitet 20.05.2025 14:03:00
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit thi...
CVE-2025-27189
- EPSS 0.04%
- Veröffentlicht 08.04.2025 20:17:09
- Zuletzt bearbeitet 30.04.2025 14:59:09
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logg...
CVE-2025-27188
- EPSS 0.07%
- Veröffentlicht 08.04.2025 20:17:09
- Zuletzt bearbeitet 01.05.2025 20:00:44
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass secur...
- EPSS 2.35%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:00
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-serv...
CVE-2021-36043
- EPSS 2.61%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:00
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code exe...
CVE-2021-36042
- EPSS 4.11%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:00
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestrict...
CVE-2021-36041
- EPSS 5.48%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:00
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could upload a specially crafted file in the 'pub/media` direc...
CVE-2021-36040
- EPSS 3.45%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:00
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to bypass file extension r...