CVE-2024-20719
- EPSS 0.63%
- Veröffentlicht 15.02.2024 14:15:46
- Zuletzt bearbeitet 21.11.2024 08:53:00
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may b...
CVE-2024-20720
- EPSS 4.82%
- Veröffentlicht 15.02.2024 14:15:46
- Zuletzt bearbeitet 21.11.2024 08:53:01
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. E...
CVE-2024-20716
- EPSS 0.14%
- Veröffentlicht 15.02.2024 14:15:45
- Zuletzt bearbeitet 21.11.2024 08:52:59
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to e...
CVE-2024-20717
- EPSS 0.82%
- Veröffentlicht 15.02.2024 14:15:45
- Zuletzt bearbeitet 21.11.2024 08:52:59
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious Ja...
CVE-2024-20718
- EPSS 0.07%
- Veröffentlicht 15.02.2024 14:15:45
- Zuletzt bearbeitet 21.11.2024 08:53:00
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a victim into pe...
CVE-2023-38249
- EPSS 1.41%
- Veröffentlicht 13.10.2023 07:15:41
- Zuletzt bearbeitet 21.11.2024 08:13:10
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that co...
CVE-2023-38250
- EPSS 1.41%
- Veröffentlicht 13.10.2023 07:15:41
- Zuletzt bearbeitet 21.11.2024 08:13:10
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that co...
CVE-2023-38251
- EPSS 0.23%
- Veröffentlicht 13.10.2023 07:15:41
- Zuletzt bearbeitet 21.11.2024 08:13:11
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled Resource Consumption vulnerability that could lead in minor application denial-of-service. Exp...
CVE-2023-38218
- EPSS 0.69%
- Veröffentlicht 13.10.2023 07:15:40
- Zuletzt bearbeitet 21.11.2024 08:13:06
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Authorization . An authenticated attacker can exploit this to achieve information exposure and p...
CVE-2023-38219
- EPSS 1.52%
- Veröffentlicht 13.10.2023 07:15:40
- Zuletzt bearbeitet 21.11.2024 08:13:06
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject...