magento

380 tracked vulnerabilities.

CVE-2021-36041 CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin pub/media Upload Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.05
CVE-2021-36040 CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin File Extension Bypass Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.03
CVE-2021-36039 MEDIUM
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
Sep 01, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-36038 MEDIUM
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
Sep 01, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-36037 MEDIUM
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
Sep 01, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-36034 CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin File Upload Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.05
CVE-2021-36033 CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
Sep 01, 2021
CVSS 9.1
EPSS 0.11
CVE-2021-36032 HIGH
Magento Commerce <2.4.2-2.3.7 - Privilege Escalation
Sep 01, 2021
CVSS 8.3
EPSS 0.01
CVE-2021-36031 HIGH
Magento Commerce <2.4.2-2.3.7 - Path Traversal
Sep 01, 2021
CVSS 7.2
EPSS 0.10
CVE-2021-36030 HIGH
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
Sep 01, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-36029 CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin Authorization Bypass Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.03
CVE-2021-36028 CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
Sep 01, 2021
CVSS 9.1
EPSS 0.11
CVE-2021-36027 MEDIUM
Magento Commerce <2.4.2-2.3.7 - XSS
Sep 01, 2021
CVSS 6.5
EPSS 0.02
CVE-2021-36026 MEDIUM
Magento Commerce <2.4.2-2.3.7 - XSS
Sep 01, 2021
CVSS 6.5
EPSS 0.02
CVE-2021-36025 CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin Customer File Code Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.05
CVE-2021-36024 CRITICAL
Adobe Commerce/Magento Open Source <=2.4.2-p1 - Admin Data Collection Command Execution
Sep 01, 2021
CVSS 9.1
EPSS 0.09
CVE-2021-36022 CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
Sep 01, 2021
CVSS 9.1
EPSS 0.11
CVE-2021-36020 HIGH
Magento Commerce <2.4.2-2.3.7 - Code Injection
Sep 01, 2021
CVSS 8.2
EPSS 0.31
CVE-2021-36012 MEDIUM
Magento Commerce <2.4.2-2.3.7 - Privilege Escalation
Sep 01, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-28585 MEDIUM
Magento < 2.3.6 and 2.4.0-2.4.2-p1 - Improper Input Validation in New Customer WebAPI
Jun 28, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-28584 MEDIUM
Magento < 2.3.6 and 2.4.0-2.4.2-p1 - Authenticated Path Traversal and Arbitrary File Write via Child Theme Creation
Jun 28, 2021
CVSS 5.4
EPSS 0.01
CVE-2021-28583 HIGH
Magento <2.4.2, 2.4.1-p1, 2.3.6-p1 - Info Disclosure
Jun 28, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-28563 MEDIUM
Magento < 2.3.7, 2.4.0-2.4.2-p1 - Unauthenticated Improper Authorization via Create Customer Endpoint
Jun 28, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-28556 MEDIUM
Magento < 2.3.7, 2.4.0-2.4.2-p1 - Unauthenticated DOM-based Cross-Site Scripting via mage-messages Cookie
Jun 28, 2021
CVSS 6.9
EPSS 0.24
CVE-2021-21064 MEDIUM
Magento UPWARD-php <1.1.4 - Path Traversal
Feb 25, 2021
CVSS 4.9
EPSS 0.01