Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Magento CRITICAL 9.8
CVE-2020-9631EPSS 7%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vu…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9632EPSS 7%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vu…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento HIGH 7.5
CVE-2020-9587EPSS 5%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnera…

Fix: after 2.3.4
Fix from $1,950 2020-06-26
Magento HIGH 7.5
CVE-2020-9591

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mit…

Fix: after 2.3.4
Fix from $1,950 2020-06-26
Magento HIGH 7.2
CVE-2020-9588

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepanc…

Fix: after 2.3.4
Fix from $1,950 2020-06-26
Magento MEDIUM 5.4
CVE-2020-9584

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting v…

Fix: after 2.3.4
Fix from $1,600 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9576EPSS 6%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9578EPSS 6%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9579EPSS 5%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vu…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9580EPSS 5%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vu…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento CRITICAL 9.8
CVE-2020-9582EPSS 6%

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…

Fix: after 2.3.4
Fix from $2,300 2020-06-26
Magento MEDIUM 6.1
CVE-2020-9577

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting v…

Fix: after 2.3.4
Fix from $1,600 2020-06-26
Magento MEDIUM 6.1
CVE-2020-9581

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting v…

Fix: after 2.3.4
Fix from $1,600 2020-06-26
Advanced Newsletter CRITICAL 9.8
CVE-2014-1634

SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH…

Fix: 2.3.5+
Fix from $2,300 2020-03-09
Magento HIGH 7.5
CVE-2020-3719

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful…

Fix: after 2.3.3
Fix from $1,950 2020-01-29
Magento MEDIUM 6.1
CVE-2020-3758

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerabilit…

Fix: after 2.3.3
Fix from $1,600 2020-01-29
Magento CRITICAL 9.8
CVE-2020-3716EPSS 14%

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulner…

Fix: after 2.3.3
Fix from $2,300 2020-01-29
Magento CRITICAL 9.8
CVE-2020-3718EPSS 8%

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successfu…

Fix: after 2.3.3
Fix from $2,300 2020-01-29
Magento MEDIUM 6.1
CVE-2020-3715

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerabilit…

Fix: after 2.3.3
Fix from $1,600 2020-01-29
Magento MEDIUM 5.3
CVE-2020-3717

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful…

Fix: after 2.3.3
Fix from $1,600 2020-01-29
Magento CRITICAL 9.8
CVE-2019-8158

An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET re…

Fix: 2.2.10 / 2.3.2+
Fix from $2,300 2019-11-06
Magento HIGH 7.2
CVE-2019-8156

A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated us…

Fix: 2.2.10 / 2.3.2+
Fix from $1,950 2019-11-06
Magento MEDIUM 5.4
CVE-2019-8132

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated use…

Fix: 2.2.10 / 2.3.2+
Fix from $1,600 2019-11-06
Magento MEDIUM 5.4
CVE-2019-8145

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated use…

Fix: 2.2.10 / 2.3.2+
Fix from $1,600 2019-11-06
Magento MEDIUM 5.4
CVE-2019-8157

A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated use…

Fix: 2.2.10 / 2.3.2+
Fix from $1,600 2019-11-06
Magento MEDIUM 6.6
CVE-2019-8232

In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an authenticated use…

Fix: 1.9.4.3 / 1.14.4.3+
Fix from $1,600 2019-11-06
Magento MEDIUM 6.1
CVE-2019-8233

In Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an unauthenticated user can inject arbitrary JavaScript code as a result of t…

Fix: 2.2.10 / 2.3.2+
Fix from $1,600 2019-11-06
Magento CRITICAL 9.8
CVE-2019-8149

Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauth…

Fix: 2.2.10 / 2.3.2+
Fix from $2,300 2019-11-06
Magento HIGH 8.8
CVE-2019-8150

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privi…

Fix: 2.2.10 / 2.3.2+
Fix from $1,950 2019-11-06
Magento HIGH 8.8
CVE-2019-8154

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privi…

Fix: 2.2.10 / 2.3.2+
Fix from $1,950 2019-11-06