Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.56% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/8/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing the application… | |
| Analizada | Media (4.3) | 0.37% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 25/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of… | |
| Analizada | Baja (2.7) | 0.39% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 25/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access.… | |
| Analizada | Alta (8.4) | 0.73% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser… | |
| Analizada | Alta (8.1) | 0.57% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized elevated access.… | |
| Analizada | Alta (8.2) | 0.53% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access leading to a limited impact… | |
| Analizada | Media (6.5) | 0.53% | — | Adobe Commerce B2B | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.… | |
| Analizada | Media (5.3) | 0.47% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Exploitation of this… | |
| Analizada | Baja (2.7) | 0.48% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by… | |
| Analizada | Media (5.3) | 0.49% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this… | |
| Analizada | Media (5.3) | 0.53% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this… | |
| Analizada | Media (4.3) | 1.0% | — | Adobe Commerce B2B | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to the vulnerable… | |
| Analizada | Media (4.3) | 0.57% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue… | |
| Modificada | Alta (8.7) | 0.80% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Media (5.4) | 0.45% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view or modify select information. Exploitation of this issue… | |
| Analizada | Media (4.3) | 0.55% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view select information. Exploitation of this issue does not… | |
| Modificada | Media (4.3) | 0.53% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to modify… | |
| Analizada | Crítica (9.1) | 17% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this… | |
| Analizada | Baja (3.7) | 0.40% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but… | |
| Analizada | Baja (3.7) | 0.40% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but… | |
| Analizada | Baja (3.5) | 0.50% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain… | |
| Analizada | Media (5.4) | 0.41% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Media (6.5) | 0.63% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.… | |
| Analizada | Media (6.5) | 0.77% | — | Adobe Commerce B2B | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.… | |
| Analizada | Media (5.3) | 0.63% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to circumvent intended security mechanisms by manipulating the logic of the… |