Show filters
355 Total Results
Displaying 181-190 of 355
Sort by:
Attacker Value
Unknown

CVE-2020-9587

Disclosure Date: June 26, 2020 (last updated November 28, 2024)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an authorization bypass vulnerability. Successful exploitation could lead to potentially unauthorized product discounts.
Attacker Value
Unknown

CVE-2020-9581

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Attacker Value
Unknown

CVE-2020-9630

Disclosure Date: June 26, 2020 (last updated November 28, 2024)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation.
Attacker Value
Unknown

CVE-2020-9584

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Attacker Value
Unknown

CVE-2020-9582

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-9583

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-9576

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-9580

Disclosure Date: June 26, 2020 (last updated November 28, 2024)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-9591

Disclosure Date: June 26, 2020 (last updated November 28, 2024)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mitigation vulnerability. Successful exploitation could lead to unauthorized access to admin panel.
Attacker Value
Unknown

CVE-2020-9578

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.