Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.77% | — | Adobe Commerce B2B | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.… | |
| Analizada | Media (4.3) | 0.52% | — | Adobe Commerce B2B | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to modify select data. Exploitation of this issue does not require… | |
| Analizada | Media (6.5) | 0.77% | — | Adobe Commerce B2B | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.… | |
| Analizada | Media (4.3) | 0.55% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to read select data. Exploitation of this issue does not require… | |
| Analizada | Media (4.3) | 0.56% | — | Adobe Commerce B2B | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not… | |
| Analizada | Media (4.3) | 0.56% | — | Adobe Commerce B2B | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not… | |
| Analizada | Alta (8.1) | 0.96% | — | Adobe Commerce B2B | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation… | |
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Alta (8.1) | 0.91% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access… | |
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s… | |
| Analizada | Alta (8.2) | 0.68% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both a… | |
| Analizada | Media (6.5) | 0.95% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user… | |
| Analizada | Alta (7.1) | 0.79% | — | Adobe Commerce B2B | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted leading… | |
| Analizada | Alta (7.5) | 1.4% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/2/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An unauthenticated attacker could exploit this vulnerability to modify… | |
| Analizada | Baja (2.7) | 0.48% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/10/2024 | 17/6/2026 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality.… | |
| Analizada | Alta (8.8) | 0.73% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/10/2024 | 17/6/2026 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauthorized access without proper credentials. Exploitation of this… | |
| Analizada | Baja (2.7) | 0.58% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/10/2024 | 17/6/2026 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this… | |
| Analizada | Baja (2.7) | 0.63% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/10/2024 | 17/6/2026 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may aid in further attacks. Exploitation of… | |
| Analizada | Baja (2.7) | 0.60% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/10/2024 | 17/6/2026 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may aid in further attacks. Exploitation of… | |
| Modificada | Media (6.5) | 0.73% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/10/2024 | 17/6/2026 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect confidentiality. Exploitation of this issue… |