CVE-2025-43585
- EPSS 0.59%
- Veröffentlicht 10.06.2025 16:15:40
- Zuletzt bearbeitet 23.06.2025 19:22:41
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass secur...
CVE-2025-43586
- EPSS 0.42%
- Veröffentlicht 10.06.2025 16:15:40
- Zuletzt bearbeitet 23.06.2025 19:22:26
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to by...
CVE-2025-27207
- EPSS 0.42%
- Veröffentlicht 10.06.2025 16:15:36
- Zuletzt bearbeitet 11.07.2025 16:42:26
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to by...
CVE-2025-27206
- EPSS 0.71%
- Veröffentlicht 10.06.2025 16:15:36
- Zuletzt bearbeitet 23.06.2025 19:25:38
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass secu...
CVE-2025-27190
- EPSS 0.84%
- Veröffentlicht 08.04.2025 20:17:12
- Zuletzt bearbeitet 23.06.2025 19:30:03
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass...
CVE-2025-27191
- EPSS 0.84%
- Veröffentlicht 08.04.2025 20:17:11
- Zuletzt bearbeitet 20.05.2025 14:30:41
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass...
CVE-2025-27192
- EPSS 0.59%
- Veröffentlicht 08.04.2025 20:17:10
- Zuletzt bearbeitet 20.05.2025 14:03:00
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit thi...
CVE-2025-27189
- EPSS 0.35%
- Veröffentlicht 08.04.2025 20:17:09
- Zuletzt bearbeitet 30.04.2025 14:59:09
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logg...
CVE-2025-27188
- EPSS 0.46%
- Veröffentlicht 08.04.2025 20:17:09
- Zuletzt bearbeitet 01.05.2025 20:00:44
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass secur...
CVE-2021-36043
- EPSS 2.61%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:13:00
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code exe...