Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | Adobe Commerce | 0 ~ 2.4.4-p8 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2024-34102 unauthenticated RCE PoC for Magento/adobe commerce | https://github.com/ex-arny/CVE-2024-34102-RCE | POC Details |
| 2 | None | https://github.com/ArturArz1/TestCVE-2024-34102 | POC Details |
| 3 | CVE-2024-34102: Unauthenticated Magento XXE | https://github.com/th3gokul/CVE-2024-34102 | POC Details |
| 4 | POC for CVE-2024-34102. A pre-authentication XML entity injection issue in Magento / Adobe Commerce. | https://github.com/bigb0x/CVE-2024-34102 | POC Details |
| 5 | CVE-2024-34102 unauthenticated RCE PoC for Magento/adobe commerce | https://github.com/dr3u1d/CVE-2024-34102-RCE | POC Details |
| 6 | None | https://github.com/11whoami99/CVE-2024-34102 | POC Details |
| 7 | A PoC demonstration , critical XML entity injection vulnerability in Magento | https://github.com/d0rb/CVE-2024-34102 | POC Details |
| 8 | CosmicSting (CVE-2024-34102) | https://github.com/Chocapikk/CVE-2024-34102 | POC Details |
| 9 | TEST CVE-2024-34102 Magento XXE | https://github.com/cmsec423/CVE-2024-34102 | POC Details |
| 10 | Magento XXE (CVE-2024-34102) | https://github.com/0x0d3ad/CVE-2024-34102 | POC Details |
| 11 | None | https://github.com/cmsec423/Magento-XXE-CVE-2024-34102 | POC Details |
| 12 | CosmicSting: critical unauthenticated XXE vulnerability in Adobe Commerce and Magento (CVE-2024-34102) | https://github.com/jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento | POC Details |
| 13 | None | https://github.com/0xhunster/CVE-2024-34102 | POC Details |
| 14 | CosmicSting (CVE-2024-34102) POC / Patch Validator | https://github.com/SamJUK/cosmicsting-validator | POC Details |
| 15 | poc for CVE-2024-34102 | https://github.com/unknownzerobit/poc | POC Details |
| 16 | CVE-2024-34102 unauthenticated RCE PoC for Magento/adobe commerce | https://github.com/Ex-Arn/CVE-2024-34102-RCE | POC Details |
| 17 | Burp Extension to test for CVE-2024-34102 | https://github.com/crynomore/CVE-2024-34102 | POC Details |
| 18 | CVE-2024-34102 unauthenticated RCE PoC for Magento/adobe commerce | https://github.com/1mpl3ment3d/CVE-2024-34102-RCE-POC | POC Details |
| 19 | Exploitation CVE-2024-34102 | https://github.com/bughuntar/CVE-2024-34102 | POC Details |
| 20 | CVE-2024-34102 Exploiter based on Python | https://github.com/bughuntar/CVE-2024-34102-Python | POC Details |
| 21 | None | https://github.com/Phantom-IN/CVE-2024-34102 | POC Details |
| 22 | CVE-2024-34102 unauthenticated RCE PoC for Magento/adobe commerce and (NEW 0DAY)? | https://github.com/ex-ARnX/CVE-2024-34102-PoC | POC Details |
| 23 | CVE-2024-34102 unauthenticated RCE PoC for Magento/adobe commerce | https://github.com/etx-Arn/CVE-2024-34102-RCE | POC Details |
| 24 | CVE-2024-34102 unauthenticated RCE PoC for Magento/adobe commerce | https://github.com/etx-Arn/CVE-2024-34102-RCE-PoC | POC Details |
| 25 | Magento 2 patch for CVE-2024-34102(aka CosmicSting). Another way(as an extension) to hotfix the security hole if you cannot apply the official patch or cannot upgrade Magento. | https://github.com/wubinworks/magento2-cosmic-sting-patch | POC Details |
| 26 | PoC for CVE-2024-34102 | https://github.com/EQSTSeminar/CVE-2024-34102 | POC Details |
| 27 | adobe commerce | https://github.com/Jhonsonwannaa/CVE-2024-34102 | POC Details |
| 28 | PoC for CVE-2024-34102 | https://github.com/EQSTLab/CVE-2024-34102 | POC Details |
| 29 | None | https://github.com/bka/magento-cve-2024-34102-exploit-cosmicstring | POC Details |
| 30 | adobe commerce | https://github.com/dream434/CVE-2024-34102 | POC Details |
| 31 | A utility for Magento 2 encryption key rotation and management. CVE-2024-34102(aka Cosmic Sting) victims can use it as an aftercare. | https://github.com/wubinworks/magento2-encryption-key-manager-cli | POC Details |
| 32 | None | https://github.com/mksundaram69/CVE-2024-34102 | POC Details |
| 33 | None | https://github.com/Koray123-debug/CVE-2024-34102 | POC Details |
| 34 | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-34102.yaml | POC Details |
| 35 | None | https://github.com/Kento-Sec/CVE-2024-34102 | POC Details |
| 36 | CVE-2024-34102 exploit for python3 | https://github.com/nmmorette/CVE-2024-34102 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-30299 | 10.0 CRITICAL | Tenable Vulnerability Disclosure | API Auth Bypass |
| CVE-2024-30300 | 9.8 CRITICAL | Tenable Vulnerability Disclosure | Sensitive Information Disclosure Via Fake FMPS Worker |
| CVE-2024-34108 | 9.1 CRITICAL | Large attack surface through legit webhook usage in Adobe Commerce |
| CVE-2024-34104 | 8.2 HIGH | Adobe Commerce | Improper Authorization (CWE-285) |
| CVE-2024-34103 | 8.1 HIGH | Customer account takeover via web API call & subsequent password reset |
| CVE-2024-34115 | 7.8 HIGH | ZDI-CAN-24054: Adobe Substance 3D Stager SKP File Parsing Out-Of-Bounds Write Remote Code |
| CVE-2024-20753 | 7.8 HIGH | Adobe Photoshop PDF File Parsing Memory Corruption Remote Code Execution Vulnerability |
| CVE-2024-26029 | 7.5 HIGH | Adobe Experience Manager | Improper Access Control (CWE-284) |
| CVE-2024-34129 | 7.5 HIGH | Acrobat Android : OverSecured Finding : Overwriting arbitrary files via attacker-controlle |
| CVE-2024-34112 | 7.5 HIGH | ColdFusion CFDOCUMENT file retrieval / access control bypass |
| CVE-2024-34109 | 7.2 HIGH | Adobe Commerce | Improper Input Validation (CWE-20) |
| CVE-2024-34110 | 7.2 HIGH | RCE in the Adobe Commerce Webhook module through a legit webhook definition |
| CVE-2024-34116 | 7.1 HIGH | Adobe Creative Cloud App Install Arbitrary Folder Delete Vulnerability can be abuse to Pri |
| CVE-2024-34111 | 6.5 MEDIUM | SSRF in service connector |
| CVE-2024-34130 | 5.5 MEDIUM | Acrobat Android : OverSecured Finding : Access to arbitrary* content providers via insecur |
| CVE-2024-30276 | 5.5 MEDIUM | Adobe Audition 2024 M2V File Parsing Memory corruption |
| CVE-2024-30285 | 5.5 MEDIUM | Adobe Audition 2024 MP4 File Parsing Null Pointer Dereference |
| CVE-2024-34113 | 5.5 MEDIUM | ColdFusion | Weak Cryptography for Passwords (CWE-261) |
| CVE-2024-30278 | 5.5 MEDIUM | Adobe Media Encoder 2024 TGA File parsing memory corruption |
| CVE-2024-26072 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
Showing top 20 of 165 CVEs. View all on vendor page → →
No comments yet