Записи Magento
224 опубликованных записей вендора magento.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,4 %
- Pre-auth RCE
- 17
- С записью об исправлении
- 91,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')65
- CWE-352 Cross-Site Request Forgery (CSRF)10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')10
- CWE-639 Authorization Bypass Through User-Controlled Key8
- CWE-434 Unrestricted Upload of File with Dangerous Type8
- CWE-285 Improper Authorization7
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
224 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
67На этой неделе | CVE-2016-4010Готовый эксплойт | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via craftedmagento · magento · CWE-74 | Критическая9,8 | — | 92,9 % | 23 янв. 2017 г. |
45В плане | CVE-2019-7139Proof of concept | An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data magento · magento · CWE-89 | Критическая9,8 | — | 18,3 % | 10 апр. 2019 г. |
44В плане | CVE-2021-21029Эксплойта нет | Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Executionmagento · magento · CWE-79 | Средняя4,8 | — | 84,6 % | 11 февр. 2021 г. |
43В плане | CVE-2015-1397Proof of concept | SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1magento · magento · CWE-89 | Средняя6,5 | — | 56,7 % | 29 апр. 2015 г. |
43В плане | CVE-2020-3716Эксплойта нет | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted damagento · magento · CWE-502 | Критическая9,8 | — | 14,0 % | 29 янв. 2020 г. |
42В плане | CVE-2020-9664Эксплойта нет | Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.magento · magento · CWE-502 | Критическая9,8 | — | 8,4 % | 22 июл. 2020 г. |
41В плане | CVE-2020-3718Эксплойта нет | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.magento · magento | Критическая9,8 | — | 7,5 % | 29 янв. 2020 г. |
41В плане | CVE-2020-9631Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Критическая9,8 | — | 7,4 % | 26 июн. 2020 г. |
41В плане | CVE-2020-9632Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Критическая9,8 | — | 7,4 % | 26 июн. 2020 г. |
41В плане | CVE-2020-9582Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Критическая9,8 | — | 5,7 % | 26 июн. 2020 г. |
41В плане | CVE-2020-9583Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Критическая9,8 | — | 5,7 % | 26 июн. 2020 г. |
41В плане | CVE-2020-9578Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Критическая9,8 | — | 5,7 % | 26 июн. 2020 г. |
41В плане | CVE-2020-9576Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Критическая9,8 | — | 5,7 % | 26 июн. 2020 г. |
41В плане | CVE-2020-9579Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Критическая9,8 | — | 5,0 % | 26 июн. 2020 г. |
41В плане | CVE-2020-9580Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Критическая9,8 | — | 5,0 % | 26 июн. 2020 г. |
40В плане | CVE-2022-34258Эксплойта нет | Adobe Commerce Stored XSS Arbitrary code executionadobe · commerce · CWE-79 | Средняя4,8 | — | 68,5 % | 16 авг. 2022 г. |
40В плане | CVE-2020-9691Эксплойта нет | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.magento · magento · CWE-79 | Критическая9,6 | — | 6,0 % | 29 июл. 2020 г. |
40В плане | CVE-2020-9585Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth secmagento · magento | Критическая9,8 | — | 4,9 % | 26 июн. 2020 г. |
40В плане | CVE-2020-9630Эксплойта нет | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic errormagento · magento | Критическая9,8 | — | 4,0 % | 26 июн. 2020 г. |
40В плане | CVE-2019-8144Эксплойта нет | A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento | Критическая9,8 | — | 2,5 % | 5 нояб. 2019 г. |
40В плане | CVE-2019-8135Эксплойта нет | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-74 | Критическая9,8 | — | 2,5 % | 5 нояб. 2019 г. |
40В плане | CVE-2019-8149Эксплойта нет | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-613 | Критическая9,8 | — | 2,1 % | 5 нояб. 2019 г. |
40В плане | CVE-2022-34256Эксплойта нет | Adobe Commerce Improper Authorization Privilege escalationadobe · commerce · CWE-285 | Критическая9,8 | — | 2,1 % | 16 авг. 2022 г. |
39Наблюдать | CVE-2014-1634Эксплойта нет | SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_categorymagento · advanced newsletter · CWE-89 | Критическая9,8 | — | 1,4 % | 9 мар. 2020 г. |
39Наблюдать | CVE-2015-8707Эксплойта нет | Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, magento · magento · CWE-200 | Критическая9,8 | — | 1,3 % | 25 сент. 2017 г. |
- CVE-2016-401067На этой неделе
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted
КритическаяCVSS 9,8Готовый эксплойтEPSS 93 %magento · magento23 янв. 2017 г.
- CVE-2019-713945В плане
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data
КритическаяCVSS 9,8Proof of conceptEPSS 18 %magento · magento10 апр. 2019 г.
- CVE-2021-2102944В плане
Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Execution
СредняяCVSS 4,8Эксплойта нетEPSS 85 %magento · magento11 февр. 2021 г.
- CVE-2015-139743В плане
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1
СредняяCVSS 6,5Proof of conceptEPSS 57 %magento · magento29 апр. 2015 г.
- CVE-2020-371643В плане
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted da
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %magento · magento29 янв. 2020 г.
- CVE-2020-966442В плане
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %magento · magento22 июл. 2020 г.
- CVE-2020-371841В плане
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %magento · magento29 янв. 2020 г.
- CVE-2020-963141В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %magento · magento26 июн. 2020 г.
- CVE-2020-963241В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %magento · magento26 июн. 2020 г.
- CVE-2020-958241В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %magento · magento26 июн. 2020 г.
- CVE-2020-958341В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %magento · magento26 июн. 2020 г.
- CVE-2020-957841В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %magento · magento26 июн. 2020 г.
- CVE-2020-957641В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %magento · magento26 июн. 2020 г.
- CVE-2020-957941В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %magento · magento26 июн. 2020 г.
- CVE-2020-958041В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %magento · magento26 июн. 2020 г.
- CVE-2022-3425840В плане
Adobe Commerce Stored XSS Arbitrary code execution
СредняяCVSS 4,8Эксплойта нетEPSS 69 %adobe · commerce16 авг. 2022 г.
- CVE-2020-969140В плане
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.
КритическаяCVSS 9,6Эксплойта нетEPSS 6 %magento · magento29 июл. 2020 г.
- CVE-2020-958540В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth sec
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %magento · magento26 июн. 2020 г.
- CVE-2020-963040В плане
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %magento · magento26 июн. 2020 г.
- CVE-2019-814440В плане
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %magento · magento5 нояб. 2019 г.
- CVE-2019-813540В плане
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %magento · magento5 нояб. 2019 г.
- CVE-2019-814940В плане
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %magento · magento5 нояб. 2019 г.
- CVE-2022-3425640В плане
Adobe Commerce Improper Authorization Privilege escalation
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %adobe · commerce16 авг. 2022 г.
- CVE-2014-163439Наблюдать
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %magento · advanced newsletter9 мар. 2020 г.
- CVE-2015-870739Наблюдать
Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use,
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %magento · magento25 сент. 2017 г.