Vulnerability intelligence
VULONE Vulnerability Database
Stay ahead of what gets exploited. Every CVE from NVD, enriched every 30 minutes with EPSS, CISA KEV, ransomware linkage and automated analysis.
Filters Show:
11 results. Sitecore Experience Manager.
Page 1 of 1| ID | Severity | Score | Technology | Weakness | CISA KEV | Exploit | EPSS | Published |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-53690 | Critical | 9.0 | SSitecore Experience Commerce +3 | Deserialization of untrusted data | Listed | Confirmed | 51% | Sep 3, 2025 |
| CVE-2025-53694 | High | 7.5 | SSitecore Experience Commerce +3 | Information exposure | — | 1 ref | 6.0% | Sep 3, 2025 |
| CVE-2025-53693 | Critical | 9.8 | SSitecore Experience Commerce +3 | CWE-470 | — | 1 ref | 15% | Sep 3, 2025 |
| CVE-2025-53691 | High | 8.8 | SSitecore Experience Commerce +3 | Deserialization of untrusted data | — | 1 ref | 1.6% | Sep 3, 2025 |
| CVE-2025-34511 | High | 8.8 | SSitecore Experience Commerce +3 | Unrestricted file upload | — | 1 ref | 30% | Jun 17, 2025 |
| CVE-2025-34510 | High | 8.8 | SSitecore Experience Commerce +3 | Relative path traversal | — | 1 ref | 24% | Jun 17, 2025 |
| CVE-2025-34509 | High | 7.5 | SSitecore Experience Commerce +3 | Hard-coded credentials | — | 1 ref | 56% | Jun 17, 2025 |
| CVE-2024-46938 | High | 7.5 | SSitecore Experience Commerce +2 | Information exposure | — | — | 47% | Sep 15, 2024 |
| CVE-2023-35813 | Critical | 9.8 | SSitecore Experience Commerce +3 | Code injection | — | — | 87% | Jun 17, 2023 |
| CVE-2023-33651 | High | 7.5 | SSitecore Experience Commerce +3 | Incorrect authorization | — | 2 refs | 1.4% | Jun 6, 2023 |
| CVE-2023-26262 | High | 7.2 | SSitecore Experience Manager +1 | Unrestricted file upload | — | 2 refs | 1.7% | Mar 14, 2023 |