Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 4.1% | — | Magento | 29/7/2020 | 17/6/2026 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (6.1) | 1.4% | — | Magento | 22/7/2020 | 17/6/2026 | Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |
| Modificada | Crítica (9.8) | 8.4% | — | Magento | 22/7/2020 | 17/6/2026 | Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (4.8) | 1.4% | — | Form Builder FOR Magento 2 Project Form Builder FOR Magento 2 | 29/6/2020 | 17/6/2026 | Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header. | |
| Modificada | Crítica (9.8) | 7.4% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 7.4% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 4.0% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation. | |
| Modificada | Alta (7.5) | 3.4% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to unauthorized access to admin panel. | |
| Modificada | Alta (7.2) | 2.9% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass. | |
| Modificada | Alta (7.5) | 5.0% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts. | |
| Modificada | Crítica (9.8) | 4.9% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (5.4) | 1.2% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |
| Modificada | Crítica (9.8) | 5.7% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.7% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (6.1) | 1.5% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |
| Modificada | Crítica (9.8) | 5.0% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.0% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.7% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (6.1) | 1.5% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure . | |
| Modificada | Crítica (9.8) | 5.7% | — | Magento | 26/6/2020 | 17/6/2026 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 1.4% | — | Magento Advanced Newsletter | 9/3/2020 | 17/6/2026 | SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO. | |
| Modificada | Alta (8.1) | 4.2% | — | Cardgate PaymentsAdobe Magento | 25/2/2020 | 17/6/2026 | An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment… | |
| Modificada | Alta (7.5) | 2.0% | — | Magentocommerce Magento | 13/2/2020 | 16/6/2026 | Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability. | |
| Modificada | Media (6.1) | 1.8% | — | Magento | 29/1/2020 | 17/6/2026 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |
| Modificada | Alta (7.5) | 3.2% | — | Magento | 29/1/2020 | 17/6/2026 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure. |