Magento kayıtları
magento üreticisine ait 224 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,4
- Pre-auth RCE
- 17
- Düzeltme kaydı olan
- %91,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')65
- CWE-352 Cross-Site Request Forgery (CSRF)10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')10
- CWE-639 Authorization Bypass Through User-Controlled Key8
- CWE-434 Unrestricted Upload of File with Dangerous Type8
- CWE-285 Improper Authorization7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
224 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
67Bu hafta | CVE-2016-4010Silahlaştırılmış | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via craftedmagento · magento · CWE-74 | Kritik9,8 | — | %92,9 | 23 Oca 2017 |
45Planlayın | CVE-2019-7139Kavram kanıtı | An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data magento · magento · CWE-89 | Kritik9,8 | — | %18,3 | 10 Nis 2019 |
44Planlayın | CVE-2021-21029İstismar yok | Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Executionmagento · magento · CWE-79 | Orta4,8 | — | %84,6 | 11 Şub 2021 |
43Planlayın | CVE-2015-1397Kavram kanıtı | SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1magento · magento · CWE-89 | Orta6,5 | — | %56,7 | 29 Nis 2015 |
43Planlayın | CVE-2020-3716İstismar yok | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted damagento · magento · CWE-502 | Kritik9,8 | — | %14,0 | 29 Oca 2020 |
42Planlayın | CVE-2020-9664İstismar yok | Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.magento · magento · CWE-502 | Kritik9,8 | — | %8,4 | 22 Tem 2020 |
41Planlayın | CVE-2020-3718İstismar yok | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.magento · magento | Kritik9,8 | — | %7,5 | 29 Oca 2020 |
41Planlayın | CVE-2020-9631İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Kritik9,8 | — | %7,4 | 26 Haz 2020 |
41Planlayın | CVE-2020-9632İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Kritik9,8 | — | %7,4 | 26 Haz 2020 |
41Planlayın | CVE-2020-9582İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Kritik9,8 | — | %5,7 | 26 Haz 2020 |
41Planlayın | CVE-2020-9583İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Kritik9,8 | — | %5,7 | 26 Haz 2020 |
41Planlayın | CVE-2020-9578İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Kritik9,8 | — | %5,7 | 26 Haz 2020 |
41Planlayın | CVE-2020-9576İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vumagento · magento · CWE-77 | Kritik9,8 | — | %5,7 | 26 Haz 2020 |
41Planlayın | CVE-2020-9579İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Kritik9,8 | — | %5,0 | 26 Haz 2020 |
41Planlayın | CVE-2020-9580İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation magento · magento | Kritik9,8 | — | %5,0 | 26 Haz 2020 |
40Planlayın | CVE-2022-34258İstismar yok | Adobe Commerce Stored XSS Arbitrary code executionadobe · commerce · CWE-79 | Orta4,8 | — | %68,5 | 16 Ağu 2022 |
40Planlayın | CVE-2020-9691İstismar yok | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.magento · magento · CWE-79 | Kritik9,6 | — | %6,0 | 29 Tem 2020 |
40Planlayın | CVE-2020-9585İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth secmagento · magento | Kritik9,8 | — | %4,9 | 26 Haz 2020 |
40Planlayın | CVE-2020-9630İstismar yok | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic errormagento · magento | Kritik9,8 | — | %4,0 | 26 Haz 2020 |
40Planlayın | CVE-2019-8144İstismar yok | A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento | Kritik9,8 | — | %2,5 | 5 Kas 2019 |
40Planlayın | CVE-2019-8135İstismar yok | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-74 | Kritik9,8 | — | %2,5 | 5 Kas 2019 |
40Planlayın | CVE-2019-8149İstismar yok | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-613 | Kritik9,8 | — | %2,1 | 5 Kas 2019 |
40Planlayın | CVE-2022-34256İstismar yok | Adobe Commerce Improper Authorization Privilege escalationadobe · commerce · CWE-285 | Kritik9,8 | — | %2,1 | 16 Ağu 2022 |
39İzleyin | CVE-2014-1634İstismar yok | SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_categorymagento · advanced newsletter · CWE-89 | Kritik9,8 | — | %1,4 | 9 Mar 2020 |
39İzleyin | CVE-2015-8707İstismar yok | Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, magento · magento · CWE-200 | Kritik9,8 | — | %1,3 | 25 Eyl 2017 |
- CVE-2016-401067Bu hafta
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted
KritikCVSS 9,8SilahlaştırılmışEPSS %93magento · magento23 Oca 2017
- CVE-2019-713945Planlayın
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data
KritikCVSS 9,8Kavram kanıtıEPSS %18magento · magento10 Nis 2019
- CVE-2021-2102944Planlayın
Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Execution
OrtaCVSS 4,8İstismar yokEPSS %85magento · magento11 Şub 2021
- CVE-2015-139743Planlayın
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1
OrtaCVSS 6,5Kavram kanıtıEPSS %57magento · magento29 Nis 2015
- CVE-2020-371643Planlayın
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted da
KritikCVSS 9,8İstismar yokEPSS %14magento · magento29 Oca 2020
- CVE-2020-966442Planlayın
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.
KritikCVSS 9,8İstismar yokEPSS %8magento · magento22 Tem 2020
- CVE-2020-371841Planlayın
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.
KritikCVSS 9,8İstismar yokEPSS %8magento · magento29 Oca 2020
- CVE-2020-963141Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
KritikCVSS 9,8İstismar yokEPSS %7magento · magento26 Haz 2020
- CVE-2020-963241Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
KritikCVSS 9,8İstismar yokEPSS %7magento · magento26 Haz 2020
- CVE-2020-958241Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
KritikCVSS 9,8İstismar yokEPSS %6magento · magento26 Haz 2020
- CVE-2020-958341Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
KritikCVSS 9,8İstismar yokEPSS %6magento · magento26 Haz 2020
- CVE-2020-957841Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
KritikCVSS 9,8İstismar yokEPSS %6magento · magento26 Haz 2020
- CVE-2020-957641Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu
KritikCVSS 9,8İstismar yokEPSS %6magento · magento26 Haz 2020
- CVE-2020-957941Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
KritikCVSS 9,8İstismar yokEPSS %5magento · magento26 Haz 2020
- CVE-2020-958041Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation
KritikCVSS 9,8İstismar yokEPSS %5magento · magento26 Haz 2020
- CVE-2022-3425840Planlayın
Adobe Commerce Stored XSS Arbitrary code execution
OrtaCVSS 4,8İstismar yokEPSS %69adobe · commerce16 Ağu 2022
- CVE-2020-969140Planlayın
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.
KritikCVSS 9,6İstismar yokEPSS %6magento · magento29 Tem 2020
- CVE-2020-958540Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth sec
KritikCVSS 9,8İstismar yokEPSS %5magento · magento26 Haz 2020
- CVE-2020-963040Planlayın
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error
KritikCVSS 9,8İstismar yokEPSS %4magento · magento26 Haz 2020
- CVE-2019-814440Planlayın
A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
KritikCVSS 9,8İstismar yokEPSS %2magento · magento5 Kas 2019
- CVE-2019-813540Planlayın
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
KritikCVSS 9,8İstismar yokEPSS %2magento · magento5 Kas 2019
- CVE-2019-814940Planlayın
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
KritikCVSS 9,8İstismar yokEPSS %2magento · magento5 Kas 2019
- CVE-2022-3425640Planlayın
Adobe Commerce Improper Authorization Privilege escalation
KritikCVSS 9,8İstismar yokEPSS %2adobe · commerce16 Ağu 2022
- CVE-2014-163439İzleyin
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category
KritikCVSS 9,8İstismar yokEPSS %1magento · advanced newsletter9 Mar 2020
- CVE-2015-870739İzleyin
Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use,
KritikCVSS 9,8İstismar yokEPSS %1magento · magento25 Eyl 2017