3.7

CVSS3.1

CVE-2025-24430 - Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it hasโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2025, 2:25 p.m.

3.5

CVSS3.1

CVE-2025-24429 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could leverage this vulnerability to bypass securityโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2025, 2:27 p.m.

4.3

CVSS3.1

CVE-2025-24436 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view select information. Exploitation of tโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2025, 2:53 p.m.

7.1

CVSS3.1

CVE-2025-24407 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low privileged attacker could exploit this vulnerability to perform actions with permissions that wereโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2025, 5:18 p.m.

8.7

CVSS3.1

CVE-2025-24438 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executedโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-24423 - Adobe Commerce | Improper Access Control (CWE-284)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to modify select data. Exploitation of this issueโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2025, 5:16 p.m.

8.1

CVSS3.1

CVE-2025-24418 - Adobe Commerce | Improper Authorization (CWE-285)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized โ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.5

CVSS3.1

CVE-2025-24406 - Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWโ€ฆ

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An unauthenticated attacker could exploit this vulnโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 17, 2025, 4:09 p.m.

8.7

CVSS3.1

CVE-2025-24417 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executedโ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

8.2

CVSS3.1

CVE-2025-24409 - Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access,โ€ฆ

๐Ÿ“… Published: Feb. 11, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2025, 5:18 p.m.
Total resulsts: 343968
Page 6266 of 34,397
ยซ previous page ยป next page
Filters