Skip to content
Noroxi

Magento records

224 published records for vendor magento.

All records

224 records
  • CVE-2016-4010
    67This week

    Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted

    CriticalCVSS 9.8WeaponizedEPSS 93%

    magento · magentoJan 23, 2017

  • An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data

    CriticalCVSS 9.8Proof of conceptEPSS 18%

    magento · magentoApr 10, 2019

  • Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Execution

    MediumCVSS 4.8No exploitEPSS 85%

    magento · magentoFeb 11, 2021

  • SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1

    MediumCVSS 6.5Proof of conceptEPSS 57%

    magento · magentoApr 29, 2015

  • Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted da

    CriticalCVSS 9.8No exploitEPSS 14%

    magento · magentoJan 29, 2020

  • Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.

    CriticalCVSS 9.8No exploitEPSS 8%

    magento · magentoJul 22, 2020

  • Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.

    CriticalCVSS 9.8No exploitEPSS 8%

    magento · magentoJan 29, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    CriticalCVSS 9.8No exploitEPSS 7%

    magento · magentoJun 26, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    CriticalCVSS 9.8No exploitEPSS 7%

    magento · magentoJun 26, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    CriticalCVSS 9.8No exploitEPSS 6%

    magento · magentoJun 26, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    CriticalCVSS 9.8No exploitEPSS 6%

    magento · magentoJun 26, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    CriticalCVSS 9.8No exploitEPSS 6%

    magento · magentoJun 26, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    CriticalCVSS 9.8No exploitEPSS 6%

    magento · magentoJun 26, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    CriticalCVSS 9.8No exploitEPSS 5%

    magento · magentoJun 26, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    CriticalCVSS 9.8No exploitEPSS 5%

    magento · magentoJun 26, 2020

  • Adobe Commerce Stored XSS Arbitrary code execution

    MediumCVSS 4.8No exploitEPSS 69%

    adobe · commerceAug 16, 2022

  • Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.

    CriticalCVSS 9.6No exploitEPSS 6%

    magento · magentoJul 29, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth sec

    CriticalCVSS 9.8No exploitEPSS 5%

    magento · magentoJun 26, 2020

  • Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error

    CriticalCVSS 9.8No exploitEPSS 4%

    magento · magentoJun 26, 2020

  • A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    CriticalCVSS 9.8No exploitEPSS 2%

    magento · magentoNov 5, 2019

  • A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    CriticalCVSS 9.8No exploitEPSS 2%

    magento · magentoNov 5, 2019

  • Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    CriticalCVSS 9.8No exploitEPSS 2%

    magento · magentoNov 5, 2019

  • Adobe Commerce Improper Authorization Privilege escalation

    CriticalCVSS 9.8No exploitEPSS 2%

    adobe · commerceAug 16, 2022

  • CVE-2014-1634
    39Monitor

    SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category

    CriticalCVSS 9.8No exploitEPSS 1%

    magento · advanced newsletterMar 9, 2020

  • CVE-2015-8707
    39Monitor

    Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use,

    CriticalCVSS 9.8No exploitEPSS 1%

    magento · magentoSep 25, 2017