4.3

CVSS3.1

CVE-2024-39416 - Unauthorized user can export Orders Sale Report

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. …

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Aug. 14, 2024, 2:34 p.m.

4.3

CVSS3.1

CVE-2024-39414 - Being able to import/export tax rates without proper privileges

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. …

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Aug. 14, 2024, 2:39 p.m.

4.3

CVSS3.1

CVE-2024-39412 - Adobe Commerce | Improper Authorization (CWE-285)

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and perform a minor integrity ch…

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Oct. 16, 2024, 1:33 p.m.

8.4

CVSS3.1

CVE-2024-39402 - Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Inj…

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation of this issue require…

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Sept. 17, 2024, 11:05 a.m.

6.8

CVSS3.1

CVE-2024-39406 - Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CW…

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerability to gain access…

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Oct. 16, 2024, 1:37 p.m.

8.1

CVSS3.1

CVE-2024-39400 - DOM XSS through integrations can impact other admins

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker to inject and execute arbitrary JavaScript code within the context of the user's browser session. Exploit…

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Aug. 14, 2024, 2:48 p.m.

4.3

CVSS3.1

CVE-2024-39404 - A user without Shop Policy Parameters section privilege can alter the shop policy parameters section

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Ex…

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Aug. 14, 2024, 2:44 p.m.

4.3

CVSS3.1

CVE-2024-39415 - An unauthorized user can export the Tax Sales Report

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. …

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Aug. 14, 2024, 2:34 p.m.

4.3

CVSS3.1

CVE-2024-39405 - Adobe Commerce | Improper Authorization (CWE-285)

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Ex…

πŸ“… Published: Aug. 14, 2024, 11:57 a.m. πŸ”„ Last Modified: Sept. 17, 2024, 11:06 a.m.

6.4

CVSS3.1

CVE-2024-6532 - Sheet to Table Live Sync for Google Sheet <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site…

The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STWT_Sheet_Table shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes …

πŸ“… Published: Aug. 14, 2024, 9:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346576
Page 8602 of 34,658
Β« previous page Β» next page
Filters