2.7

CVSS3.1

CVE-2025-27192 - Adobe Commerce | Insufficiently Protected Credentials (CWE-522)

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to pr…

πŸ“… Published: April 8, 2025, 8:17 p.m. πŸ”„ Last Modified: May 20, 2025, 2:03 p.m.

4.3

CVSS3.1

CVE-2025-27188 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploi…

πŸ“… Published: April 8, 2025, 8:17 p.m. πŸ”„ Last Modified: May 1, 2025, 8 p.m.

4.3

CVSS3.1

CVE-2025-27189 - Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to th…

πŸ“… Published: April 8, 2025, 8:17 p.m. πŸ”„ Last Modified: April 30, 2025, 2:59 p.m.

9.1

CVSS3.1

CVE-2025-22871 - Request smuggling due to acceptance of invalid chunked data in net/http

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

πŸ“… Published: April 8, 2025, 8:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2024-12556 - Kibana Prototype Pollution can lead to code injection

Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

πŸ“… Published: April 8, 2025, 8:04 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.2

CVSS3.1

CVE-2025-30287 - ColdFusion | Improper Authentication (CWE-287)

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leverage this vulnerability to bypass security protec…

πŸ“… Published: April 8, 2025, 8:03 p.m. πŸ”„ Last Modified: April 21, 2025, 6:37 p.m.

6.8

CVSS3.1

CVE-2025-30293 - ColdFusion | Improper Input Validation (CWE-20)

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized write access. Exploit…

πŸ“… Published: April 8, 2025, 8:03 p.m. πŸ”„ Last Modified: April 21, 2025, 6:39 p.m.

6.1

CVSS3.1

CVE-2025-30292 - ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's br…

πŸ“… Published: April 8, 2025, 8:03 p.m. πŸ”„ Last Modified: April 14, 2025, 3:57 p.m.

8.7

CVSS3.1

CVE-2025-30290 - ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to bypass security prote…

πŸ“… Published: April 8, 2025, 8:02 p.m. πŸ”„ Last Modified: May 12, 2025, 4:40 p.m.

9.1

CVSS3.1

CVE-2025-30282 - ColdFusion | Improper Authentication (CWE-287)

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and ex…

πŸ“… Published: April 8, 2025, 8:02 p.m. πŸ”„ Last Modified: April 23, 2025, 4:45 p.m.
Total resulsts: 345302
Page 5559 of 34,531
Β« previous page Β» next page
Filters