adobe

7,148 tracked vulnerabilities.

CVE-2024-39415 MEDIUM
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Security Feature Bypass via Improper Authorization
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39414 MEDIUM
Adobe Commerce <=2.4.7-p1 - Improper Authorization leading to Security Feature Bypass
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39413 MEDIUM
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Security Feature Bypass via Improper Authorization
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39412 MEDIUM
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Improper Authorization
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39411 MEDIUM
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Security Feature Bypass via Improper Authorization
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39410 MEDIUM
Adobe Commerce < 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 - Cross-Site Request Forgery
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39409 MEDIUM
Adobe Commerce < 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 - Cross-Site Request Forgery
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39408 MEDIUM
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Cross-Site Request Forgery
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39407 MEDIUM
Adobe Commerce < 2.4.3 - Improper Authorization
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39406 MEDIUM
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Authenticated Path Traversal and Arbitrary File Read
Aug 14, 2024
CVSS 6.8
EPSS 0.01
CVE-2024-39405 MEDIUM
Adobe Commerce 2.4.7-p1 2.4.6-p6 2.4.5-p8 2.4.4-p9 and earlier - Security Feature Bypass via Improper Authorization
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39404 MEDIUM
Adobe Commerce < 2.4.3 - Improper Authorization
Aug 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39403 HIGH
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Stored Cross-Site Scripting in Form Fields
Aug 14, 2024
CVSS 7.6
EPSS 0.03
CVE-2024-39402 HIGH
Adobe Commerce < 2.4.3 - Authenticated OS Command Injection
Aug 14, 2024
CVSS 8.4
EPSS 0.03
CVE-2024-39401 HIGH
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Authenticated OS Command Injection
Aug 14, 2024
CVSS 8.4
EPSS 0.03
CVE-2024-39400 HIGH
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - DOM-based Cross-Site Scripting
Aug 14, 2024
CVSS 8.1
EPSS 0.01
CVE-2024-39399 HIGH
Adobe Commerce < 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 - Path Traversal and Arbitrary File Read
Aug 14, 2024
CVSS 7.7
EPSS 0.01
CVE-2024-39398 HIGH
Adobe Commerce < 2.4.3 - Improper Restriction of Excessive Authentication Attempts
Aug 14, 2024
CVSS 7.4
EPSS 0.00
CVE-2024-39397 CRITICAL
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Unrestricted Upload of File with Dangerous Type
Aug 14, 2024
CVSS 9.0
EPSS 0.09
CVE-2024-41864 HIGH
Substance 3D Designer < 14.0 - Out-of-bounds Write via Malicious File
Aug 14, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-41863 MEDIUM
Substance 3D Sampler < 4.5.1 - Out-of-bounds Read via Malicious File
Aug 14, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-41862 MEDIUM
Substance 3D Sampler < 4.5.1 - Out-of-bounds Read via Malicious File
Aug 14, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-41861 MEDIUM
Substance 3D Sampler < 4.5.1 - Out-of-bounds Read via Malicious File
Aug 14, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-41860 MEDIUM
Substance 3D Sampler < 4.5.1 - Out-of-bounds Read via Malicious File
Aug 14, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-41858 HIGH
Adobe InCopy < 18.5.2 - Integer Overflow or Wraparound via Malicious File
Aug 14, 2024
CVSS 7.8
EPSS 0.00