6.5

CVSS3.1

CVE-2025-24427 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthoโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 17, 2025, 3:44 p.m.

6.5

CVSS3.1

CVE-2025-24426 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthoโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2025, 5:16 p.m.

5.4

CVSS3.1

CVE-2025-24428 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executedโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: March 3, 2025, 3:31 p.m.

8.7

CVSS3.1

CVE-2025-24410 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executedโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.5

CVSS3.1

CVE-2025-24408 - Adobe Commerce | Information Exposure (CWE-200)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue doโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: July 12, 2025, 3:26 p.m.

4.3

CVSS3.1

CVE-2025-24435 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorizedโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: Feb. 27, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2025-21162 - Photoshop Elements | Creation of Temporary File in Directory with Incorrect Permissions (CWE-379)

Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that a victim must โ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:35 p.m. ๐Ÿ”„ Last Modified: July 25, 2025, 8:02 p.m.

7.7

CVSS3.1

CVE-2025-26494 - Server Side Request Forgery vulnerability in Tableau Server

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5.

๐Ÿ“… Published: Feb. 11, 2025, 5:33 p.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 3:10 p.m.

7.8

CVSS3.1

CVE-2025-21161 - Substance3D - Designer | Out-of-bounds Write (CWE-787)

Substance3D - Designer versions 14.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“… Published: Feb. 11, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 6:58 p.m.

7.8

CVSS3.1

CVE-2025-21160 - Illustrator | Integer Underflow (Wrap or Wraparound) (CWE-191)

Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“… Published: Feb. 11, 2025, 5:27 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.
Total resulsts: 343935
Page 6264 of 34,394
ยซ previous page ยป next page
Filters