5.3

CVSS3.1

CVE-2025-27206 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Expl…

πŸ“… Published: June 10, 2025, 4:08 p.m. πŸ”„ Last Modified: June 23, 2025, 7:25 p.m.

8.1

CVSS3.1

CVE-2025-43586 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized elev…

πŸ“… Published: June 10, 2025, 4:08 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

8.4

CVSS3.1

CVE-2025-47110 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

πŸ“… Published: June 10, 2025, 4:08 p.m. πŸ”„ Last Modified: July 15, 2025, 6:40 p.m.

6.5

CVSS3.1

CVE-2025-27207 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read…

πŸ“… Published: June 10, 2025, 4:08 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

8.2

CVSS3.1

CVE-2025-43585 - Adobe Commerce | Improper Authorization (CWE-285)

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access leading…

πŸ“… Published: June 10, 2025, 4:08 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

7

CVSS4.0

CVE-2025-4678 - Remote Code Execution leads to Command Injection

Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

πŸ“… Published: June 10, 2025, 3:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-4653 - Remote Code Execution leads to Command Injection

Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

πŸ“… Published: June 10, 2025, 3:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-49143 - Nautobot may allows uploaded media files to be accessible without authentication

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROOT directory, including DeviceType image attachments as well as images attached to a Location, Device, or Rack, are served to users via a URL endpoint …

πŸ“… Published: June 10, 2025, 3:43 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 10:34 p.m.

6

CVSS4.0

CVE-2025-49142 - Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating

Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or prior to 1.6.32 are potentially affected. Due to insufficient security configuration of the Jinja2 templating feature used in computed fields, custom links, etc. in Nautobot, a m…

πŸ“… Published: June 10, 2025, 3:40 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 10:36 p.m.

4.9

CVSS3.1

CVE-2025-48937 - matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events …

πŸ“… Published: June 10, 2025, 3:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5092 of 34,919
Β« previous page Β» next page
Filters