Записи Adobe
7 713 опубликованных записей вендора adobe.
Профиль для исследователя
- Попали в KEV
- 82 · 1,1 %
- С эксплойтом
- 110 · 1,4 %
- Pre-auth RCE
- 2 338
- С записью об исправлении
- 16,3 %
- Медиана: публикация → KEV
- 2571 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1 371
- CWE-125 Out-of-bounds Read1 078
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer948
- CWE-787 Out-of-bounds Write917
- CWE-416 Use After Free683
- CWE-20 Improper Input Validation227
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
7 713 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2024-34102Готовый эксплойт | XXE can expose crypt key and other secrets granting full admin accessadobe · commerce · CWE-611 | Критическая9,8 | KEV | 100,0 % | 13 июн. 2024 г. |
99Срочно | CVE-2023-29300Готовый эксплойт | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionadobe · coldfusion · CWE-502 | Критическая9,8 | KEV | 100,0 % | 12 июл. 2023 г. |
99Срочно | CVE-2018-15961Готовый эксплойт | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploaadobe · coldfusion · CWE-434 | Критическая9,8 | KEV | 100,0 % | 25 сент. 2018 г. |
99Срочно | CVE-2015-3113Готовый эксплойт | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Критическая9,8 | KEV | 99,9 % | 23 июн. 2015 г. |
99Срочно | CVE-2014-0497Готовый эксплойт | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Критическая9,8 | KEV | 99,9 % | 5 февр. 2014 г. |
99Срочно | CVE-2010-2861Готовый эксплойт | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to readobe · coldfusion · CWE-22 | Критическая9,8 | KEV | 99,7 % | 11 авг. 2010 г. |
99Срочно | CVE-2015-5119Готовый эксплойт | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Критическая9,8 | KEV | 99,3 % | 8 июл. 2015 г. |
99Срочно | CVE-2022-24086Готовый эксплойт | Adobe Commerce checkout improper input validation leads to remote code executionadobe · commerce · CWE-20 | Критическая9,8 | KEV | 99,2 % | 16 февр. 2022 г. |
98Срочно | CVE-2023-38203Готовый эксплойт | Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCEadobe · coldfusion · CWE-502 | Критическая9,8 | KEV | 97,1 % | 20 июл. 2023 г. |
98Срочно | CVE-2015-0313Готовый эксплойт | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Критическая9,8 | KEV | 95,3 % | 2 февр. 2015 г. |
97Срочно | CVE-2016-4117Готовый эксплойт | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Критическая9,8 | KEV | 94,4 % | 10 мая 2016 г. |
97Срочно | CVE-2015-5122Готовый эксплойт | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Критическая9,8 | KEV | 94,0 % | 14 июл. 2015 г. |
97Срочно | CVE-2013-0625Готовый эксплойт | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeadobe · coldfusion · CWE-287 | Критическая9,8 | KEV | 93,8 % | 8 янв. 2013 г. |
97Срочно | CVE-2013-0632Готовый эксплойт | administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitradobe · coldfusion · CWE-276 | Критическая9,8 | KEV | 93,6 % | 16 янв. 2013 г. |
96Срочно | CVE-2017-3066Готовый эксплойт | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializaadobe · coldfusion · CWE-502 | Критическая9,8 | KEV | 90,6 % | 27 апр. 2017 г. |
96Срочно | CVE-2011-2462Готовый эксплойт | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x adobe · acrobat · CWE-787 | Критическая9,8 | KEV | 88,5 % | 7 дек. 2011 г. |
96Срочно | CVE-2025-54253Готовый эксплойт | Adobe Experience Manager | Incorrect Authorization (CWE-863)adobe · experience manager forms · CWE-863 | Критическая10,0 | KEV | 88,0 % | 5 авг. 2025 г. |
95Срочно | CVE-2011-0611Готовый эксплойт | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | Высокая8,8 | KEV | 99,4 % | 13 апр. 2011 г. |
95Срочно | CVE-2015-0311Готовый эксплойт | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throuadobe · flash player | Критическая9,8 | KEV | 85,6 % | 23 янв. 2015 г. |
94Срочно | CVE-2009-0927Готовый эксплойт | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to eadobe · acrobat reader · CWE-20 | Высокая8,8 | KEV | 96,6 % | 19 мар. 2009 г. |
94Срочно | CVE-2025-54236Готовый эксплойт | Adobe Commerce | Improper Input Validation (CWE-20)adobe · commerce · CWE-20 | Критическая9,1 | KEV | 94,5 % | 9 сент. 2025 г. |
93Срочно | CVE-2023-26360Готовый эксплойт | Adobe ColdFusion Improper Access Control Arbitrary code executionadobe · coldfusion · CWE-284 | Высокая8,6 | KEV | 97,3 % | 23 мар. 2023 г. |
93Срочно | CVE-2013-3346Готовый эксплойт | Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a adobe · acrobat · CWE-787 | Критическая9,8 | KEV | 78,9 % | 30 авг. 2013 г. |
92Срочно | CVE-2026-71362Готовый эксплойт | Adobe Commerce | Incorrect Authorization (CWE-863)adobe · commerce · CWE-863 | Критическая9,1 | KEV | 87,5 % | 11 авг. 2026 г. |
91Срочно | CVE-2008-2992Готовый эксплойт | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file tadobe · acrobat · CWE-787 | Высокая7,8 | KEV | 98,5 % | 4 нояб. 2008 г. |
- CVE-2024-3410299Срочно
XXE can expose crypt key and other secrets granting full admin access
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · commerce13 июн. 2024 г.
- CVE-2023-2930099Срочно
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · coldfusion12 июл. 2023 г.
- CVE-2018-1596199Срочно
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · coldfusion25 сент. 2018 г.
- CVE-2015-311399Срочно
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player23 июн. 2015 г.
- CVE-2014-049799Срочно
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player5 февр. 2014 г.
- CVE-2010-286199Срочно
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to re
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · coldfusion11 авг. 2010 г.
- CVE-2015-511999Срочно
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · flash player8 июл. 2015 г.
- CVE-2022-2408699Срочно
Adobe Commerce checkout improper input validation leads to remote code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · commerce16 февр. 2022 г.
- CVE-2023-3820398Срочно
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %adobe · coldfusion20 июл. 2023 г.
- CVE-2015-031398Срочно
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %adobe · flash player2 февр. 2015 г.
- CVE-2016-411797Срочно
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player10 мая 2016 г.
- CVE-2015-512297Срочно
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player14 июл. 2015 г.
- CVE-2013-062597Срочно
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · coldfusion8 янв. 2013 г.
- CVE-2013-063297Срочно
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · coldfusion16 янв. 2013 г.
- CVE-2017-306696Срочно
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializa
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 91 %adobe · coldfusion27 апр. 2017 г.
- CVE-2011-246296Срочно
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 89 %adobe · acrobat7 дек. 2011 г.
- CVE-2025-5425396Срочно
Adobe Experience Manager | Incorrect Authorization (CWE-863)
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 88 %adobe · experience manager forms5 авг. 2025 г.
- CVE-2011-061195Срочно
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %adobe · flash player13 апр. 2011 г.
- CVE-2015-031195Срочно
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %adobe · flash player23 янв. 2015 г.
- CVE-2009-092794Срочно
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to e
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 97 %adobe · acrobat reader19 мар. 2009 г.
- CVE-2025-5423694Срочно
Adobe Commerce | Improper Input Validation (CWE-20)
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 95 %adobe · commerce9 сент. 2025 г.
- CVE-2023-2636093Срочно
Adobe ColdFusion Improper Access Control Arbitrary code execution
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 97 %adobe · coldfusion23 мар. 2023 г.
- CVE-2013-334693Срочно
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 79 %adobe · acrobat30 авг. 2013 г.
- CVE-2026-7136292Срочно
Adobe Commerce | Incorrect Authorization (CWE-863)
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 88 %adobe · commerce11 авг. 2026 г.
- CVE-2008-299291Срочно
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file t
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 98 %adobe · acrobat4 нояб. 2008 г.