Adobe records
7,713 published records for vendor adobe.
Researcher profile
- Entered KEV
- 82 · 1.1%
- Weaponized
- 110 · 1.4%
- Pre-auth RCE
- 2,338
- With a fix record
- 16.3%
- Median publish → KEV
- 2571 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1,371
- CWE-125 Out-of-bounds Read1,078
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer948
- CWE-787 Out-of-bounds Write917
- CWE-416 Use After Free683
- CWE-20 Improper Input Validation227
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
7,713 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2024-34102Weaponized | XXE can expose crypt key and other secrets granting full admin accessadobe · commerce · CWE-611 | Critical9.8 | KEV | 100.0% | Jun 13, 2024 |
99Now | CVE-2023-29300Weaponized | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionadobe · coldfusion · CWE-502 | Critical9.8 | KEV | 100.0% | Jul 12, 2023 |
99Now | CVE-2018-15961Weaponized | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploaadobe · coldfusion · CWE-434 | Critical9.8 | KEV | 100.0% | Sep 25, 2018 |
99Now | CVE-2015-3113Weaponized | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Critical9.8 | KEV | 99.9% | Jun 23, 2015 |
99Now | CVE-2014-0497Weaponized | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Critical9.8 | KEV | 99.9% | Feb 5, 2014 |
99Now | CVE-2010-2861Weaponized | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to readobe · coldfusion · CWE-22 | Critical9.8 | KEV | 99.7% | Aug 11, 2010 |
99Now | CVE-2015-5119Weaponized | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Critical9.8 | KEV | 99.3% | Jul 8, 2015 |
99Now | CVE-2022-24086Weaponized | Adobe Commerce checkout improper input validation leads to remote code executionadobe · commerce · CWE-20 | Critical9.8 | KEV | 99.2% | Feb 16, 2022 |
98Now | CVE-2023-38203Weaponized | Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCEadobe · coldfusion · CWE-502 | Critical9.8 | KEV | 97.1% | Jul 20, 2023 |
98Now | CVE-2015-0313Weaponized | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Critical9.8 | KEV | 95.3% | Feb 2, 2015 |
97Now | CVE-2016-4117Weaponized | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Critical9.8 | KEV | 94.4% | May 10, 2016 |
97Now | CVE-2015-5122Weaponized | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Critical9.8 | KEV | 94.0% | Jul 14, 2015 |
97Now | CVE-2013-0625Weaponized | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeadobe · coldfusion · CWE-287 | Critical9.8 | KEV | 93.8% | Jan 8, 2013 |
97Now | CVE-2013-0632Weaponized | administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitradobe · coldfusion · CWE-276 | Critical9.8 | KEV | 93.6% | Jan 16, 2013 |
96Now | CVE-2017-3066Weaponized | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializaadobe · coldfusion · CWE-502 | Critical9.8 | KEV | 90.6% | Apr 27, 2017 |
96Now | CVE-2011-2462Weaponized | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x adobe · acrobat · CWE-787 | Critical9.8 | KEV | 88.5% | Dec 7, 2011 |
96Now | CVE-2025-54253Weaponized | Adobe Experience Manager | Incorrect Authorization (CWE-863)adobe · experience manager forms · CWE-863 | Critical10.0 | KEV | 88.0% | Aug 5, 2025 |
95Now | CVE-2011-0611Weaponized | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | High8.8 | KEV | 99.4% | Apr 13, 2011 |
95Now | CVE-2015-0311Weaponized | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throuadobe · flash player | Critical9.8 | KEV | 85.6% | Jan 23, 2015 |
94Now | CVE-2009-0927Weaponized | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to eadobe · acrobat reader · CWE-20 | High8.8 | KEV | 96.6% | Mar 19, 2009 |
94Now | CVE-2025-54236Weaponized | Adobe Commerce | Improper Input Validation (CWE-20)adobe · commerce · CWE-20 | Critical9.1 | KEV | 94.5% | Sep 9, 2025 |
93Now | CVE-2023-26360Weaponized | Adobe ColdFusion Improper Access Control Arbitrary code executionadobe · coldfusion · CWE-284 | High8.6 | KEV | 97.3% | Mar 23, 2023 |
93Now | CVE-2013-3346Weaponized | Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a adobe · acrobat · CWE-787 | Critical9.8 | KEV | 78.9% | Aug 30, 2013 |
92Now | CVE-2026-71362Weaponized | Adobe Commerce | Incorrect Authorization (CWE-863)adobe · commerce · CWE-863 | Critical9.1 | KEV | 87.5% | Aug 11, 2026 |
91Now | CVE-2008-2992Weaponized | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file tadobe · acrobat · CWE-787 | High7.8 | KEV | 98.5% | Nov 4, 2008 |
- CVE-2024-3410299Now
XXE can expose crypt key and other secrets granting full admin access
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · commerceJun 13, 2024
- CVE-2023-2930099Now
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · coldfusionJul 12, 2023
- CVE-2018-1596199Now
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · coldfusionSep 25, 2018
- CVE-2015-311399Now
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerJun 23, 2015
- CVE-2014-049799Now
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerFeb 5, 2014
- CVE-2010-286199Now
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to re
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · coldfusionAug 11, 2010
- CVE-2015-511999Now
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
CriticalCVSS 9.8KEVWeaponizedEPSS 99%adobe · flash playerJul 8, 2015
- CVE-2022-2408699Now
Adobe Commerce checkout improper input validation leads to remote code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 99%adobe · commerceFeb 16, 2022
- CVE-2023-3820398Now
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 97%adobe · coldfusionJul 20, 2023
- CVE-2015-031398Now
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
CriticalCVSS 9.8KEVWeaponizedEPSS 95%adobe · flash playerFeb 2, 2015
- CVE-2016-411797Now
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · flash playerMay 10, 2016
- CVE-2015-512297Now
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · flash playerJul 14, 2015
- CVE-2013-062597Now
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · coldfusionJan 8, 2013
- CVE-2013-063297Now
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · coldfusionJan 16, 2013
- CVE-2017-306696Now
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializa
CriticalCVSS 9.8KEVWeaponizedEPSS 91%adobe · coldfusionApr 27, 2017
- CVE-2011-246296Now
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x
CriticalCVSS 9.8KEVWeaponizedEPSS 89%adobe · acrobatDec 7, 2011
- CVE-2025-5425396Now
Adobe Experience Manager | Incorrect Authorization (CWE-863)
CriticalCVSS 10.0KEVWeaponizedEPSS 88%adobe · experience manager formsAug 5, 2025
- CVE-2011-061195Now
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
HighCVSS 8.8KEVWeaponizedEPSS 99%adobe · flash playerApr 13, 2011
- CVE-2015-031195Now
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu
CriticalCVSS 9.8KEVWeaponizedEPSS 86%adobe · flash playerJan 23, 2015
- CVE-2009-092794Now
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to e
HighCVSS 8.8KEVWeaponizedEPSS 97%adobe · acrobat readerMar 19, 2009
- CVE-2025-5423694Now
Adobe Commerce | Improper Input Validation (CWE-20)
CriticalCVSS 9.1KEVWeaponizedEPSS 95%adobe · commerceSep 9, 2025
- CVE-2023-2636093Now
Adobe ColdFusion Improper Access Control Arbitrary code execution
HighCVSS 8.6KEVWeaponizedEPSS 97%adobe · coldfusionMar 23, 2023
- CVE-2013-334693Now
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a
CriticalCVSS 9.8KEVWeaponizedEPSS 79%adobe · acrobatAug 30, 2013
- CVE-2026-7136292Now
Adobe Commerce | Incorrect Authorization (CWE-863)
CriticalCVSS 9.1KEVWeaponizedEPSS 88%adobe · commerceAug 11, 2026
- CVE-2008-299291Now
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file t
HighCVSS 7.8KEVWeaponizedEPSS 98%adobe · acrobatNov 4, 2008