VendorsAdobemagento2.4.4
Vulnerabilities

Adobe Magento 2.4.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

105CVEs
CVE-2025-24435
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-02-11 · Modified
4.3EPSS 0.005
CVE-2024-39408
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2024-08-14 · Analyzed
4.3EPSS 0.005
CVE-2024-39410
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2024-08-14 · Analyzed
4.3EPSS 0.005
CVE-2024-39409
Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)
Published 2024-08-14 · Analyzed
4.3EPSS 0.005
CVE-2024-39404
A user without Shop Policy Parameters section privilege can alter the shop policy parameters section
Published 2024-08-14 · Analyzed
4.3EPSS 0.005
CVE-2024-39417
An unauthorized user can export the Shipping Report
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39415
An unauthorized user can export the Tax Sales Report
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39414
Being able to import/export tax rates without proper privileges
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39413
An unauthorized user can export the Invoiced Sales Report
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39411
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39419
A user without ship permissions can ship the orders
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39405
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39412
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39407
Adobe Commerce | Improper Authorization (CWE-285)
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2024-39416
Unauthorized user can export Orders Sale Report
Published 2024-08-14 · Analyzed
4.3EPSS 0.004
CVE-2025-24432
Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Published 2025-02-11 · Analyzed
3.7EPSS 0.004
CVE-2025-24430
Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Published 2025-02-11 · Analyzed
3.7EPSS 0.004
CVE-2025-24429
Adobe Commerce | Improper Access Control (CWE-284)
Published 2025-02-11 · Analyzed
3.5EPSS 0.005
CVE-2024-45120
Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Published 2024-10-10 · Analyzed
3.1EPSS 0.004
CVE-2023-29293
Adobe Commerce | Improper Input Validation (CWE-20)
Published 2023-06-15 · Modified
2.7EPSS 0.010
CVE-2024-45134
Adobe Commerce | Information Exposure (CWE-200)
Published 2024-10-10 · Analyzed
2.7EPSS 0.006
CVE-2024-45133
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
2.7EPSS 0.006
CVE-2024-45135
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
2.7EPSS 0.006
CVE-2025-27192
Adobe Commerce | Insufficiently Protected Credentials (CWE-522)
Published 2025-04-08 · Analyzed
2.7EPSS 0.005
CVE-2024-45149
Adobe Commerce | Improper Access Control (CWE-284)
Published 2024-10-10 · Analyzed
2.7EPSS 0.005
← Prev3 / 3