Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2019-7912 A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by a… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.2 CVE-2019-7913 A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 MEDIUM 6.5 CVE-2019-7904 Insufficient enforcement of user access controls in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could enable … Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 5.3 CVE-2019-7898 Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1… Magento 1.9.4.2 / 1.14.4.2+ Fix from $1,6002019-08-02 MEDIUM 5.3 CVE-2019-7899 Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Ma… Magento 1.9.4.2 / 1.14.4.2+ Fix from $1,6002019-08-02 HIGH 8.8 CVE-2019-7876 A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 8.8 CVE-2019-7885 Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, … Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.5 CVE-2019-7886 A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is u… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.3 CVE-2019-7890 An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 MEDIUM 6.5 CVE-2019-7874 A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can re… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 6.5 CVE-2019-7888 An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticat… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 6.5 CVE-2019-7889 An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magen… Magento 1.9.4.2 / 1.14.4.2+ Fix from $1,6002019-08-02 MEDIUM 6.1 CVE-2019-7877 A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior t… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 5.4 CVE-2019-7881 A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 5.4 CVE-2019-7882 A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.… Magento 1.9.4.2 / 1.14.4.2+ Fix from $1,6002019-08-02 HIGH 8.8 CVE-2019-7865 A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magent… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 8.8 CVE-2019-7871 A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbit… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.5 CVE-2019-7858 A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive infor… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.5 CVE-2019-7859 A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could re… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.5 CVE-2019-7860 A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 pri… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.5 CVE-2019-7861 Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento … Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 MEDIUM 6.5 CVE-2019-7872 An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 5.3 CVE-2019-7864 An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento … Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 HIGH 7.5 CVE-2019-7849 A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior t… Magento 1.9.4.2 / 1.14.4.2+ Fix from $1,9502019-08-02 HIGH 7.5 CVE-2019-7854 An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can l… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 MEDIUM 6.5 CVE-2019-7851 A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to uninten… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 5.3 CVE-2019-7852 A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specifi… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 5.3 CVE-2019-7855 A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 CRITICAL 9.8 CVE-2019-7139EPSS 18% An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. … Magento 1.9.4.1 / 1.14.4.1+ Fix from $2,3002019-04-10 MEDIUM 6.5 CVE-2018-5301 Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an a… Magento 2.0.10 / 2.1.2+ Fix from $1,6002018-01-08