İçeriğe atla
Noroxi

Magento kayıtları

magento üreticisine ait 224 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %0,4
Pre-auth RCE
17
Düzeltme kaydı olan
%91,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

224 kayıt
  • CVE-2016-4010
    67Bu hafta

    Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted

    KritikCVSS 9,8SilahlaştırılmışEPSS %93

    magento · magento23 Oca 2017

  • CVE-2019-7139
    45Planlayın

    An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data

    KritikCVSS 9,8Kavram kanıtıEPSS %18

    magento · magento10 Nis 2019

  • CVE-2021-21029
    44Planlayın

    Magento Commerce Reflected Cross-site Scripting Vulnerability Could Lead To Arbitrary JavaScript Execution

    OrtaCVSS 4,8İstismar yokEPSS %85

    magento · magento11 Şub 2021

  • CVE-2015-1397
    43Planlayın

    SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1

    OrtaCVSS 6,5Kavram kanıtıEPSS %57

    magento · magento29 Nis 2015

  • CVE-2020-3716
    43Planlayın

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted da

    KritikCVSS 9,8İstismar yokEPSS %14

    magento · magento29 Oca 2020

  • CVE-2020-9664
    42Planlayın

    Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %8

    magento · magento22 Tem 2020

  • CVE-2020-3718
    41Planlayın

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %8

    magento · magento29 Oca 2020

  • CVE-2020-9631
    41Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    KritikCVSS 9,8İstismar yokEPSS %7

    magento · magento26 Haz 2020

  • CVE-2020-9632
    41Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    KritikCVSS 9,8İstismar yokEPSS %7

    magento · magento26 Haz 2020

  • CVE-2020-9582
    41Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    KritikCVSS 9,8İstismar yokEPSS %6

    magento · magento26 Haz 2020

  • CVE-2020-9583
    41Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    KritikCVSS 9,8İstismar yokEPSS %6

    magento · magento26 Haz 2020

  • CVE-2020-9578
    41Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    KritikCVSS 9,8İstismar yokEPSS %6

    magento · magento26 Haz 2020

  • CVE-2020-9576
    41Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vu

    KritikCVSS 9,8İstismar yokEPSS %6

    magento · magento26 Haz 2020

  • CVE-2020-9579
    41Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    KritikCVSS 9,8İstismar yokEPSS %5

    magento · magento26 Haz 2020

  • CVE-2020-9580
    41Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation

    KritikCVSS 9,8İstismar yokEPSS %5

    magento · magento26 Haz 2020

  • CVE-2022-34258
    40Planlayın

    Adobe Commerce Stored XSS Arbitrary code execution

    OrtaCVSS 4,8İstismar yokEPSS %69

    adobe · commerce16 Ağu 2022

  • CVE-2020-9691
    40Planlayın

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability.

    KritikCVSS 9,6İstismar yokEPSS %6

    magento · magento29 Tem 2020

  • CVE-2020-9585
    40Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth sec

    KritikCVSS 9,8İstismar yokEPSS %5

    magento · magento26 Haz 2020

  • CVE-2020-9630
    40Planlayın

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error

    KritikCVSS 9,8İstismar yokEPSS %4

    magento · magento26 Haz 2020

  • CVE-2019-8144
    40Planlayın

    A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    KritikCVSS 9,8İstismar yokEPSS %2

    magento · magento5 Kas 2019

  • CVE-2019-8135
    40Planlayın

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    KritikCVSS 9,8İstismar yokEPSS %2

    magento · magento5 Kas 2019

  • CVE-2019-8149
    40Planlayın

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    KritikCVSS 9,8İstismar yokEPSS %2

    magento · magento5 Kas 2019

  • CVE-2022-34256
    40Planlayın

    Adobe Commerce Improper Authorization Privilege escalation

    KritikCVSS 9,8İstismar yokEPSS %2

    adobe · commerce16 Ağu 2022

  • CVE-2014-1634
    39İzleyin

    SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category

    KritikCVSS 9,8İstismar yokEPSS %1

    magento · advanced newsletter9 Mar 2020

  • CVE-2015-8707
    39İzleyin

    Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use,

    KritikCVSS 9,8İstismar yokEPSS %1

    magento · magento25 Eyl 2017