Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.65% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue… | |
| Modificada | Media (4.3) | 0.74% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Business Logic Errors vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue… | |
| Modificada | Baja (2.7) | 1.0% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An admin privileged attacker could leverage this vulnerability to impact the availability of a user's minor feature.… | |
| Modificada | Media (4.9) | 0.95% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection… | |
| Modificada | Media (4.9) | 1.1% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection… | |
| Modificada | Media (5.3) | 0.63% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass a minor functionality. Exploitation of this issue does not… | |
| Modificada | Media (6.5) | 0.88% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an XML Injection vulnerability. An attacker with low privileges can trigger a specially crafted script to a security feature bypass. Exploitation of this issue does not require user interaction. | |
| Modificada | Media (4.3) | 0.65% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A privileged attacker could leverage this vulnerability to modify a minor functionality of another user's data.… | |
| Modificada | Media (5.3) | 0.71% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability that could lead to a security feature bypass. An attacker could leverage this vulnerability to leak minor user data. Exploitation of this issue does not require user… | |
| Modificada | Alta (7.5) | 1.0% | — | Adobe CommerceAdobe Magento | 15/6/2023 | 17/6/2026 | Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to leak another user's data. Exploitation of this issue does not require… | |
| Modificada | Media (4.3) | 0.56% | — | Adobe CommerceAdobe Magento Open Source | 27/3/2023 | 17/6/2026 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure. | |
| Modificada | Media (5.3) | 0.96% | — | Adobe CommerceAdobe Magento Open Source | 27/3/2023 | 17/6/2026 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not… | |
| Modificada | Media (4.8) | 58% | — | Adobe CommerceAdobe Magento Open Source | 27/3/2023 | 17/6/2026 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they… | |
| Modificada | Alta (7.5) | 0.93% | — | Adobe CommerceAdobe Magento Open Source | 27/3/2023 | 17/6/2026 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not… | |
| Modificada | Alta (7.5) | 0.99% | — | Openmage Magento | 28/1/2023 | 17/6/2026 | OpenMage LTS is an e-commerce platform. Versions prior to 19.4.22 and 20.0.19 contain an infinite loop in malicious code filter in certain conditions. Versions 19.4.22 and 20.0.19 have a fix for this issue. There are no known workarounds. | |
| Modificada | Alta (7.2) | 1.2% | — | Openmage Magento | 27/1/2023 | 17/6/2026 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 19.4.22 and 20.0.19 contain a patch for this issue. | |
| Modificada | Alta (8.8) | 1.2% | — | Openmage Magento | 27/1/2023 | 17/6/2026 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remote code. Versions 19.4.22 and 20.0.19 contain a patch for this issue. | |
| Modificada | Alta (7.2) | 1.3% | — | Openmage Magento | 27/1/2023 | 17/6/2026 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4.22 and 20.0.19 contain a patch for this issue. | |
| Modificada | Alta (7.2) | 1.3% | — | Openmage Magento | 27/1/2023 | 17/6/2026 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue. | |
| Modificada | Media (4.3) | 0.38% | — | Openmage Magento | 27/1/2023 | 17/6/2026 | Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior to 19.4.22 and 20.0.19 are vulnerable to Cross-Site Request Forgery. The password reset form is vulnerable to CSRF between the time the reset password link is clicked and user submits new password.… | |
| Modificada | Alta (8.8) | 1.2% | — | Adobe CommerceMagento | 20/10/2022 | 17/6/2026 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation. | |
| Modificada | Media (5.4) | 11% | 💥 PoC | Adobe CommerceAdobe Magento Open Source | 14/10/2022 | 17/6/2026 | Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution. | |
| Modificada | Media (5.3) | 1.3% | — | Adobe CommerceAdobe Magento Open Source | 14/10/2022 | 17/6/2026 | Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require… | |
| Modificada | Media (5.3) | 0.82% | — | Adobe CommerceAdobe Magento Commerce | 19/8/2022 | 17/6/2026 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation… | |
| Modificada | Media (5.3) | 1.6% | — | Adobe CommerceMagento | 16/8/2022 | 17/6/2026 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of… |