CVE-2025-26495 – “Tableau Server Cleartext Storage of Sensitive Information”
The following table lists the changes that have been made to the CVE-2025-26495 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 11, 2025 Action […]
CVE-2025-26494 – Salesforce Tableau Server SSRF Authentication Bypass
The following table lists the changes that have been made to the CVE-2025-26494 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 11, 2025 Action […]
CVE-2025-24438 – Adobe Commerce Stored Cross-Site Scripting (XSS) Vulnerability
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A […]
CVE-2025-24437 – Adobe Commerce Improper Access Control Privilege Escalation
The following table lists the changes that have been made to the CVE-2025-24437 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 11, 2025 Action […]
CVE-2025-24436 – Adobe Commerce Privilege Escalation Improper Access Control
The following table lists the changes that have been made to the CVE-2025-24436 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 11, 2025 Action […]
CVE-2025-24435 – Adobe Commerce Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-24435 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 11, 2025 Action […]
CVE-2025-24434 – Adobe Commerce Privilege Escalation Improper Authorization
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session […]
CVE-2025-24426 – Adobe Commerce Improper Access Control Vulnerability Allows Security Feature Bypass
The following table lists the changes that have been made to the CVE-2025-24426 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 11, 2025 Action […]
CVE-2025-24432 – Adobe Commerce TOCTOU Race Condition Security Feature Bypass
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing security mechanisms. Exploitation of […]
CVE-2025-24430 – Adobe Commerce TOCTOU Race Condition Vulnerability
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing security mechanisms. Exploitation of […]