Every advisory we track
The whole index, synced from the National Vulnerability Database and CISA's Known Exploited Vulnerabilities catalogue. The page used to print the number and not the list, which is a figure nobody can check.
Tracked is not the same as reported. A scan raises a finding only where we have written the step-by-step repair for it, because an exact fix command cannot be generated honestly from a CVE record. The right-hand column says which is which, and what changed records every time one moves from one column to the other.
| Advisory | CVSS | Exploited | Published | On a report? |
|---|---|---|---|---|
|
CVE-2026-75650
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code exec… |
10.0 | in the wild KEV 2026-09-08 | 2026-09-07 | StyleSmuggler |
|
CVE-2024-34102
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vuln… |
9.8 | in the wild KEV 2024-07-17 | 2024-06-13 | CosmicSting |
|
CVE-2022-24086
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout proc… |
9.8 | in the wild KEV 2022-02-15 | 2022-02-16 | TrojanOrder |
|
CVE-2026-71362
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili… |
9.1 | in the wild KEV 2026-09-24 | 2026-08-11 | the August authorisation flaw |
|
CVE-2025-54236
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerabil… |
9.1 | in the wild KEV 2025-10-24 | 2025-09-09 | SessionReaper |
Most of what is here is long fixed — the index goes back years, and an advisory against a release nobody runs any more is history rather than a risk. That is precisely why a report names the handful we can actually place on your store instead of listing all of these.
From intelligence vault 2026.09.6, released 2026-09-25. Index last synced 10 hours ago.