Vulnerabilities (CVE)

Filtered by vendor Adobe Subscribe
Filtered by product Commerce
Total 143 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-35689 1 Adobe 2 Commerce, Magento Open Source 2022-10-19 N/A 5.3 MEDIUM
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
CVE-2022-34256 2 Adobe, Magento 2 Commerce, Magento 2022-08-31 N/A 9.8 CRITICAL
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
CVE-2021-39864 1 Adobe 2 Commerce, Magento Open Source 2021-10-21 4.3 MEDIUM 6.5 MEDIUM
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.