Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2019-7912
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by a…
Magento
2.1.18 / 2.2.9+
HIGH 7.2
CVE-2019-7913
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Thi…
Magento
2.1.18 / 2.2.9+
MEDIUM 6.5
CVE-2019-7904
Insufficient enforcement of user access controls in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could enable …
Magento
2.1.18 / 2.2.9+
MEDIUM 5.3
CVE-2019-7898
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1…
Magento
1.9.4.2 / 1.14.4.2+
MEDIUM 5.3
CVE-2019-7899
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Ma…
Magento
1.9.4.2 / 1.14.4.2+
HIGH 8.8
CVE-2019-7876
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated…
Magento
2.1.18 / 2.2.9+
HIGH 8.8
CVE-2019-7885
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, …
Magento
2.1.18 / 2.2.9+
HIGH 7.5
CVE-2019-7886
A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is u…
Magento
2.1.18 / 2.2.9+
HIGH 7.3
CVE-2019-7890
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to…
Magento
2.1.18 / 2.2.9+
MEDIUM 6.5
CVE-2019-7874
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can re…
Magento
2.1.18 / 2.2.9+
MEDIUM 6.5
CVE-2019-7888
An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticat…
Magento
2.1.18 / 2.2.9+
MEDIUM 6.5
CVE-2019-7889
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magen…
Magento
1.9.4.2 / 1.14.4.2+
MEDIUM 6.1
CVE-2019-7877
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior t…
Magento
2.1.18 / 2.2.9+
MEDIUM 5.4
CVE-2019-7881
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be…
Magento
2.1.18 / 2.2.9+
MEDIUM 5.4
CVE-2019-7882
A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.…
Magento
1.9.4.2 / 1.14.4.2+
HIGH 8.8
CVE-2019-7865
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magent…
Magento
2.1.18 / 2.2.9+
HIGH 8.8
CVE-2019-7871
A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbit…
Magento
2.1.18 / 2.2.9+
HIGH 7.5
CVE-2019-7858
A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive infor…
Magento
2.1.18 / 2.2.9+
HIGH 7.5
CVE-2019-7859
A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could re…
Magento
2.1.18 / 2.2.9+
HIGH 7.5
CVE-2019-7860
A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 pri…
Magento
2.1.18 / 2.2.9+
HIGH 7.5
CVE-2019-7861
Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento …
Magento
2.1.18 / 2.2.9+
MEDIUM 6.5
CVE-2019-7872
An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.…
Magento
2.1.18 / 2.2.9+
MEDIUM 5.3
CVE-2019-7864
An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento …
Magento
2.1.18 / 2.2.9+
HIGH 7.5
CVE-2019-7849
A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior t…
Magento
1.9.4.2 / 1.14.4.2+
HIGH 7.5
CVE-2019-7854
An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can l…
Magento
2.1.18 / 2.2.9+
MEDIUM 6.5
CVE-2019-7851
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to uninten…
Magento
2.1.18 / 2.2.9+
MEDIUM 5.3
CVE-2019-7852
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specifi…
Magento
2.1.18 / 2.2.9+
MEDIUM 5.3
CVE-2019-7855
A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user…
Magento
2.1.18 / 2.2.9+
CRITICAL 9.8
CVE-2019-7139EPSS 18%
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. …
Magento
1.9.4.1 / 1.14.4.1+
MEDIUM 6.5
CVE-2018-5301
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an a…
Magento
2.0.10 / 2.1.2+