CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. |
| Exploit 1mo ago | 8.1 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access affecting Confidentiality and Integrity. Exploitation of this issue does not require user interaction. |
| 1mo ago | 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. |
| Exploit 1mo ago | 8.2 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both a High impact to confidentiality and Low impact to integrity. Exploitation of this issue does not require user interaction. |
| Exploit 1mo ago | 7.1 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted leading to both a High impact to confidentiality and Low impact to integrity. Exploitation of this issue does not require user interaction. |
| Exploit 1mo ago | 7.5 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An unauthenticated attacker could exploit this vulnerability to modify files that are stored outside the restricted directory. Exploitation of this issue does not require user interaction. |
| 1mo ago | 7.3 | Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability |
| 1mo ago | 7.3 | Visual Studio Code Elevation of Privilege Vulnerability |
| 1mo ago | 7 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability |
| 1mo ago | 7.8 | Windows Disk Cleanup Tool Elevation of Privilege Vulnerability |
| 1mo ago | 7.1 | Windows Setup Files Cleanup Elevation of Privilege Vulnerability |
| KEV 1mo ago | 7.8 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| 1mo ago | 7 | Windows Core Messaging Elevation of Privileges Vulnerability |
| Exploit 1mo ago | 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| Exploit 1mo ago | 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| Exploit 1mo ago | 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| Exploit 1mo ago | 8 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| Exploit 1mo ago | 7.8 | Microsoft Office Remote Code Execution Vulnerability |
| Exploit 1mo ago | 7.8 | Microsoft Excel Remote Code Execution Vulnerability |
| Exploit 1mo ago | 7.8 | Microsoft Office Remote Code Execution Vulnerability |
| KEV 1mo ago | 7.1 | Windows Storage Elevation of Privilege Vulnerability |
| Exploit 1mo ago | 7.8 | Microsoft Excel Remote Code Execution Vulnerability |
| Exploit 1mo ago | 7.8 | Microsoft Excel Remote Code Execution Vulnerability |
| Exploit 1mo ago | 7.8 | Microsoft Excel Remote Code Execution Vulnerability |
| 1mo ago | 7.8 | Microsoft Excel Information Disclosure Vulnerability |
| Exploit 1mo ago | 7.8 | Microsoft Excel Remote Code Execution Vulnerability |
| Exploit 1mo ago | 7.1 | DHCP Client Service Remote Code Execution Vulnerability |
| Exploit 1mo ago | 8.1 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
| 1mo ago | 7.8 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
| 1mo ago | 7.8 | Windows Installer Elevation of Privilege Vulnerability |