Known vulnerabilities in Adobe Commerce (formerly Magento Commerce) - page 8

Vendor: Adobe
Software CPE: cpe:2.3:a:adobe:magento_commerce:*:*:*:*:*:*:*:*
Total vulnerabilities: 341
Public exploits: 10
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Adobe Commerce (formerly Magento Commerce) Adobe Commerce (formerly Magento Commerce) is affected by 341 known vulnerabilities: 5 critical, 34 high, 103 medium, 199 low Critical High Medium Low

Vulnerabilities (341)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU94054 - Improper Access Control
CVE-2024-34107
CWE-284 Medium
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 10.07.2024 SB2024071008
#VU94052 - Improper Authentication
CVE-2024-34106
CWE-287 Medium
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 10.07.2024 SB2024071008
#VU94050 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-34105
CWE-79 Low
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 10.07.2024 SB2024071008
#VU94048 - Unrestricted Upload of File with Dangerous Type
CVE-2024-34110
CWE-434 Low
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 10.07.2024 SB2024071008
#VU94046 - Improper input validation
CVE-2024-34109
CWE-20 Low
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 10.07.2024 SB2024071008
#VU94045 - Improper input validation
CVE-2024-34108
CWE-20 Low
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 10.07.2024 SB2024071008
#VU94038 - Improper Authorization
CVE-2024-34104
CWE-285 High
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 10.07.2024 SB2024071008
#VU94037 - Improper Authentication
CVE-2024-34103
CWE-287 High
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 09.07.2024 SB2024071008
#VU91983 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-34102
CWE-611 High
Available
Exploited
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 12.06.2024 SB2024071008
#VU91981 - Server-Side Request Forgery (SSRF)
CVE-2024-34111
CWE-918 High
No
No
2.3.7-p4-ext-8, 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6, 2.4.7-p1 12.06.2024 SB2024071008
#VU88313 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20759
CWE-79 Medium
No
No
2.3.7-p4-ext-7, 2.4.0-ext-7, 2.4.1-ext-7, 2.4.2-ext-7, 2.4.3-ext-7, 2.4.4-p8, 2.4.5-p7, 2.4.6-p5, 2.4.7 09.04.2024 SB2024040975
#VU88311 - Improper input validation
CVE-2024-20758
CWE-20 High
No
No
2.3.7-p4-ext-7, 2.4.0-ext-7, 2.4.1-ext-7, 2.4.2-ext-7, 2.4.3-ext-7, 2.4.4-p8, 2.4.5-p7, 2.4.6-p5, 2.4.7 09.04.2024 SB2024040975
#VU86467 - Cross-Site Request Forgery (CSRF)
CVE-2024-20718
CWE-352 Medium
No
No
2.3.7-p4-ext-6, 2.4.0-ext-6, 2.4.1-ext-6, 2.4.2-ext-6, 2.4.3-ext-6, 2.4.4-p7, 2.4.5-p6, 2.4.6-p4 13.02.2024 SB2024021368
#VU86466 - Resource exhaustion
CVE-2024-20716
CWE-400 Low
No
No
2.3.7-p4-ext-6, 2.4.0-ext-6, 2.4.1-ext-6, 2.4.2-ext-6, 2.4.3-ext-6, 2.4.4-p7, 2.4.5-p6, 2.4.6-p4 13.02.2024 SB2024021368
#VU86465 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20720
CWE-78 Medium
No
No
2.3.7-p4-ext-6, 2.4.0-ext-6, 2.4.1-ext-6, 2.4.2-ext-6, 2.4.3-ext-6, 2.4.4-p7, 2.4.5-p6, 2.4.6-p4 13.02.2024 SB2024021368
#VU86464 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20717
CWE-79 Low
No
No
2.3.7-p4-ext-6, 2.4.0-ext-6, 2.4.1-ext-6, 2.4.2-ext-6, 2.4.3-ext-6, 2.4.4-p7, 2.4.5-p6, 2.4.6-p4 13.02.2024 SB2024021368
SB2024022805
#VU86463 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20719
CWE-79 Low
No
No
2.3.7-p4-ext-6, 2.4.0-ext-6, 2.4.1-ext-6, 2.4.2-ext-6, 2.4.3-ext-6, 2.4.4-p7, 2.4.5-p6, 2.4.6-p4 13.02.2024 SB2024021368
#VU81788 - Improper Authorization
CVE-2023-38220
CWE-285 Medium
No
No
2.3.7-p4-ext-5, 2.4.0-ext-5, 2.4.1-ext-5, 2.4.2-ext-5, 2.4.3-ext-5, 2.4.4-p6, 2.4.5-p5, 2.4.6-p3, 2.4.7-beta2 10.10.2023 SB2023101082
#VU81786 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-38219
CWE-79 Low
No
No
2.3.7-p4-ext-5, 2.4.0-ext-5, 2.4.1-ext-5, 2.4.2-ext-5, 2.4.3-ext-5, 2.4.4-p6, 2.4.5-p5, 2.4.6-p3, 2.4.7-beta2 10.10.2023 SB2023101082
#VU81785 - Improper input validation
CVE-2023-38218
CWE-20 High
No
No
2.3.7-p4-ext-5, 2.4.0-ext-5, 2.4.1-ext-5, 2.4.2-ext-5, 2.4.3-ext-5, 2.4.4-p6, 2.4.5-p5, 2.4.6-p3, 2.4.7-beta2 10.10.2023 SB2023101082


Showing elements 141 - 160 out of 341