Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-02-11 CVE-2025-21419 Unspecified vulnerability in Microsoft products
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.1
2025-02-11 CVE-2025-21420 Unspecified vulnerability in Microsoft products
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.8
2025-02-11 CVE-2025-24036 Unspecified vulnerability in Microsoft Autoupdate
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
local
high complexity
microsoft
7.0
2025-02-11 CVE-2025-24039 Visual Studio Code Elevation of Privilege Vulnerability
local
low complexity
CWE-427
7.3
2025-02-11 CVE-2025-24042 Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
local
low complexity
CWE-284
7.3
2025-02-11 CVE-2025-24406 Path Traversal vulnerability in Adobe Commerce
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass.
network
low complexity
adobe CWE-22
7.5
2025-02-11 CVE-2025-24407 Incorrect Authorization vulnerability in Adobe Commerce B2B
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass.
network
low complexity
adobe CWE-863
7.1
2025-02-11 CVE-2025-24408 Unspecified vulnerability in Adobe Commerce
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation.
network
low complexity
adobe
6.5
2025-02-11 CVE-2025-24409 Incorrect Authorization vulnerability in Adobe Commerce
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass.
network
low complexity
adobe CWE-863
8.2
2025-02-11 CVE-2025-24410 Cross-site Scripting vulnerability in Adobe Commerce
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe CWE-79
8.7