CVE-2024-20719
- EPSS 0.63%
- Published 15.02.2024 14:15:46
- Last modified 21.11.2024 08:53:00
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may b...
CVE-2024-20720
- EPSS 4.82%
- Published 15.02.2024 14:15:46
- Last modified 21.11.2024 08:53:01
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. E...
CVE-2024-20716
- EPSS 0.14%
- Published 15.02.2024 14:15:45
- Last modified 21.11.2024 08:52:59
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to e...
CVE-2024-20717
- EPSS 0.82%
- Published 15.02.2024 14:15:45
- Last modified 21.11.2024 08:52:59
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious Ja...
CVE-2024-20718
- EPSS 0.07%
- Published 15.02.2024 14:15:45
- Last modified 21.11.2024 08:53:00
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a victim into pe...
CVE-2023-38249
- EPSS 1.41%
- Published 13.10.2023 07:15:41
- Last modified 21.11.2024 08:13:10
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that co...
CVE-2023-38250
- EPSS 1.41%
- Published 13.10.2023 07:15:41
- Last modified 21.11.2024 08:13:10
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that co...
CVE-2023-38251
- EPSS 0.23%
- Published 13.10.2023 07:15:41
- Last modified 21.11.2024 08:13:11
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled Resource Consumption vulnerability that could lead in minor application denial-of-service. Exp...
CVE-2023-38218
- EPSS 0.69%
- Published 13.10.2023 07:15:40
- Last modified 21.11.2024 08:13:06
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Authorization . An authenticated attacker can exploit this to achieve information exposure and p...
CVE-2023-38219
- EPSS 1.52%
- Published 13.10.2023 07:15:40
- Last modified 21.11.2024 08:13:06
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject...