Перейти к содержимому
Noroxi

Записи Magento

224 опубликованных записей вендора magento.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 0,4 %
Pre-auth RCE
17
С записью об исправлении
91,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

224 записей
  • CVE-2016-4010
    67На этой неделе

    Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted

    КритическаяCVSS 9,8Готовый эксплойтEPSS 93 %

    magento · magento23 янв. 2017 г.

  • CVE-2019-7139
    45В плане

    An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data

    КритическаяCVSS 9,8Proof of conceptEPSS 18 %

    magento · magento10 апр. 2019 г.

  • CVE-2021-21029
    44В плане

    Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Execution

    СредняяCVSS 4,8Эксплойта нетEPSS 85 %

    magento · magento11 февр. 2021 г.

  • CVE-2015-1397
    43В плане

    SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1

    СредняяCVSS 6,5Proof of conceptEPSS 57 %

    magento · magento29 апр. 2015 г.

  • CVE-2020-3716
    43В плане

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted da

    КритическаяCVSS 9,8Эксплойта нетEPSS 14 %

    magento · magento29 янв. 2020 г.

  • CVE-2020-9664
    42В плане

    Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    magento · magento22 июл. 2020 г.

  • CVE-2020-3718
    41В плане

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    magento · magento29 янв. 2020 г.

  • CVE-2020-9631
    41В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    magento · magento26 июн. 2020 г.

  • CVE-2020-9632
    41В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    magento · magento26 июн. 2020 г.

  • CVE-2020-9582
    41В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    magento · magento26 июн. 2020 г.

  • CVE-2020-9583
    41В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    magento · magento26 июн. 2020 г.

  • CVE-2020-9578
    41В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    magento · magento26 июн. 2020 г.

  • CVE-2020-9576
    41В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    magento · magento26 июн. 2020 г.

  • CVE-2020-9579
    41В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    magento · magento26 июн. 2020 г.

  • CVE-2020-9580
    41В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    magento · magento26 июн. 2020 г.

  • CVE-2022-34258
    40В плане

    Adobe Commerce Stored XSS Arbitrary code execution

    СредняяCVSS 4,8Эксплойта нетEPSS 69 %

    adobe · commerce16 авг. 2022 г.

  • CVE-2020-9691
    40В плане

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.

    КритическаяCVSS 9,6Эксплойта нетEPSS 6 %

    magento · magento29 июл. 2020 г.

  • CVE-2020-9585
    40В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth sec

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    magento · magento26 июн. 2020 г.

  • CVE-2020-9630
    40В плане

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    magento · magento26 июн. 2020 г.

  • CVE-2019-8144
    40В плане

    A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    magento · magento5 нояб. 2019 г.

  • CVE-2019-8135
    40В плане

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    magento · magento5 нояб. 2019 г.

  • CVE-2019-8149
    40В плане

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    magento · magento5 нояб. 2019 г.

  • CVE-2022-34256
    40В плане

    Adobe Commerce Improper Authorization Privilege escalation

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    adobe · commerce16 авг. 2022 г.

  • CVE-2014-1634
    39Наблюдать

    SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    magento · advanced newsletter9 мар. 2020 г.

  • CVE-2015-8707
    39Наблюдать

    Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use,

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    magento · magento25 сент. 2017 г.