Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | Adobe Commerce | 0 ~ 2.4.4-p15 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | This is a tiny lab that simulates the core idea reported for CVE-2025-54236 (“SessionReaper”) | https://github.com/amalpvatayam67/day01-sessionreaper-lab | POC Details |
| 2 | Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one. | https://github.com/wubinworks/magento2-session-reaper-patch | POC Details |
| 3 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-54236.yaml | POC Details |
| 4 | cve-2025-54236 poc | https://github.com/Baba01hacker666/cve-2025-54236 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-54261 | 10.0 CRITICAL | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' |
| CVE-2025-54256 | 8.6 HIGH | Dreamweaver Desktop | Cross-Site Request Forgery (CSRF) (CWE-352) |
| CVE-2025-54257 | 7.8 HIGH | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2025-54258 | 7.8 HIGH | Substance3D - Modeler | Use After Free (CWE-416) |
| CVE-2025-54260 | 7.8 HIGH | Substance3D - Modeler | Out-of-bounds Read (CWE-125) |
| CVE-2025-54259 | 7.8 HIGH | Substance3D - Modeler | Integer Overflow or Wraparound (CWE-190) |
| CVE-2025-54244 | 7.8 HIGH | Substance3D - Viewer | Heap-based Buffer Overflow (CWE-122) |
| CVE-2025-54243 | 7.8 HIGH | Substance3D - Viewer | Out-of-bounds Write (CWE-787) |
| CVE-2025-54245 | 7.8 HIGH | Substance3D - Viewer | Out-of-bounds Write (CWE-787) |
| CVE-2025-54242 | 7.8 HIGH | Premiere Pro | Use After Free (CWE-416) |
| CVE-2025-54248 | 7.7 HIGH | Adobe Experience Manager | Improper Input Validation (CWE-20) |
| CVE-2025-54249 | 6.5 MEDIUM | Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2025-54247 | 6.5 MEDIUM | Adobe Experience Manager | Improper Input Validation (CWE-20) |
| CVE-2025-54246 | 6.5 MEDIUM | Adobe Experience Manager | Incorrect Authorization (CWE-863) |
| CVE-2025-54240 | 5.5 MEDIUM | After Effects | Out-of-bounds Read (CWE-125) |
| CVE-2025-54239 | 5.5 MEDIUM | After Effects | Out-of-bounds Read (CWE-125) |
| CVE-2025-54241 | 5.5 MEDIUM | After Effects | Out-of-bounds Read (CWE-125) |
| CVE-2025-54252 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-54250 | 4.9 MEDIUM | Adobe Experience Manager | Improper Input Validation (CWE-20) |
| CVE-2025-54251 | 4.3 MEDIUM | Adobe Experience Manager | XML Injection (aka Blind XPath Injection) (CWE-91) |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet