Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.6) | 0.22% | — | Openmage Magento | 6/11/2025 | 17/6/2026 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable… | |
| Analizada | Media (6.5) | 0.43% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to elevated privileges that increase… | |
| Analizada | Media (4.8) | 0.27% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a… | |
| Analizada | Media (5.9) | 0.55% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the… | |
| Analizada | Alta (8.1) | 0.60% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious… | |
| Analizada | Alta (8.1) | 0.60% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and maintain unauthorized access. Exploitation of this issue does not… | |
| Aplazada | Alta (8.8) | 0.38% | — | Codazon Magento ThemesAI | 1/10/2025 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload injected into the cat parameter. | |
| Aplazada | Media (5.9) | 0.22% | — | Modern Minds Magento 2 Wordpress IntegrationAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modern Minds Magento 2 WordPress Integration m2wp allows Stored XSS.This issue affects Magento 2 WordPress Integration: from n/a through <= 1.4.2.1. | |
| Analizada | Crítica (9.1) | 95% | ⚠ Explotación activa💥 Exploit | Adobe CommerceAdobe Commerce B2BAdobe Magento | 9/9/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue… | |
| Analizada | Media (5.3) | 0.66% | — | Adobe CommerceAdobe MagentoAdobe Commerce B2B | 12/8/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to modify… | |
| Analizada | Media (5.9) | 0.40% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/8/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability by manipulating the timing between the… | |
| Analizada | Alta (8.7) | 0.64% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/8/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be exploited by a low-privileged attacker to inject malicious scripts into vulnerable form fields. A successful attacker can abuse this to… | |
| Analizada | Alta (7.5) | 0.60% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/8/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.… | |
| Analizada | Alta (8.1) | 0.88% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/8/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing unintended actions on a web application where… | |
| Analizada | Alta (7.5) | 0.56% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/8/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing the application… | |
| Analizada | Media (4.3) | 0.37% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 25/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of… | |
| Analizada | Baja (2.7) | 0.39% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 25/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access.… | |
| Analizada | Alta (8.4) | 0.73% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser… | |
| Analizada | Alta (8.1) | 0.57% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized elevated access.… | |
| Analizada | Alta (8.2) | 0.53% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access leading to a limited impact… | |
| Analizada | Media (5.3) | 0.47% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Exploitation of this… | |
| Analizada | Baja (2.7) | 0.48% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by… | |
| Analizada | Media (5.3) | 0.49% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this… | |
| Analizada | Media (5.3) | 0.53% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this… | |
| Analizada | Media (4.3) | 0.57% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue… |