magento
380 tracked vulnerabilities.
CVE-2021-36041
CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin pub/media Upload Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.05
CVE-2021-36040
CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin File Extension Bypass Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.03
CVE-2021-36039
MEDIUM
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
Sep 01, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-36038
MEDIUM
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
Sep 01, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-36037
MEDIUM
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
Sep 01, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-36034
CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin File Upload Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.05
CVE-2021-36033
CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
Sep 01, 2021
CVSS 9.1
EPSS 0.11
CVE-2021-36032
HIGH
Magento Commerce <2.4.2-2.3.7 - Privilege Escalation
Sep 01, 2021
CVSS 8.3
EPSS 0.01
CVE-2021-36031
HIGH
Magento Commerce <2.4.2-2.3.7 - Path Traversal
Sep 01, 2021
CVSS 7.2
EPSS 0.10
CVE-2021-36030
HIGH
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
Sep 01, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-36029
CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin Authorization Bypass Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.03
CVE-2021-36028
CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
Sep 01, 2021
CVSS 9.1
EPSS 0.11
CVE-2021-36027
MEDIUM
Magento Commerce <2.4.2-2.3.7 - XSS
Sep 01, 2021
CVSS 6.5
EPSS 0.02
CVE-2021-36026
MEDIUM
Magento Commerce <2.4.2-2.3.7 - XSS
Sep 01, 2021
CVSS 6.5
EPSS 0.02
CVE-2021-36025
CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin Customer File Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.05
CVE-2021-36024
CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin Data Collection Command Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.09
CVE-2021-36022
CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
Sep 01, 2021
CVSS 9.1
EPSS 0.11
CVE-2021-36020
HIGH
Magento Commerce <2.4.2-2.3.7 - Code Injection
Sep 01, 2021
CVSS 8.2
EPSS 0.31
CVE-2021-36012
MEDIUM
Magento Commerce <2.4.2-2.3.7 - Privilege Escalation
Sep 01, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-28585
MEDIUM
Magento < 2.3.6 and 2.4.0-2.4.2-p1 - Improper Input Validation in New Customer WebAPI
Jun 28, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-28584
MEDIUM
Magento < 2.3.6 and 2.4.0-2.4.2-p1 - Authenticated Path Traversal and Arbitrary File Write via Child Theme Creation
Jun 28, 2021
CVSS 5.4
EPSS 0.01
CVE-2021-28583
HIGH
Magento <2.4.2, 2.4.1-p1, 2.3.6-p1 - Info Disclosure
Jun 28, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-28563
MEDIUM
Magento < 2.3.7, 2.4.0-2.4.2-p1 - Unauthenticated Improper Authorization via Create Customer Endpoint
Jun 28, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-28556
MEDIUM
Magento < 2.3.7, 2.4.0-2.4.2-p1 - Unauthenticated DOM-based Cross-Site Scripting via mage-messages Cookie
Jun 28, 2021
CVSS 6.9
EPSS 0.24
CVE-2021-21064
MEDIUM
Magento UPWARD-php <1.1.4 - Path Traversal
Feb 25, 2021
CVSS 4.9
EPSS 0.01