İçeriğe atla
Noroxi

adobe kayıtları

adobe üreticisine ait 7.713 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
82 · %1,1
Silahlaştırılmış
110 · %1,4
Pre-auth RCE
2.338
Düzeltme kaydı olan
%16,3
Yayından KEV’e ortanca
2571 gün

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

7.713 kayıt
  • XXE can expose crypt key and other secrets granting full admin access

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · commerce13 Haz 2024

  • Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · coldfusion12 Tem 2023

  • Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · coldfusion25 Eyl 2018

  • Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · flash player23 Haz 2015

  • Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · flash player5 Şub 2014

  • Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to re

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · coldfusion11 Ağu 2010

  • Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    adobe · flash player8 Tem 2015

  • Adobe Commerce checkout improper input validation leads to remote code execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    adobe · commerce16 Şub 2022

  • Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    adobe · coldfusion20 Tem 2023

  • Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    adobe · flash player2 Şub 2015

  • Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94

    adobe · flash player10 May 2016

  • Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94

    adobe · flash player14 Tem 2015

  • Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94

    adobe · coldfusion8 Oca 2013

  • administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94

    adobe · coldfusion16 Oca 2013

  • Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializa

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %91

    adobe · coldfusion27 Nis 2017

  • Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %89

    adobe · acrobat7 Ara 2011

  • Adobe Experience Manager | Incorrect Authorization (CWE-863)

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %88

    adobe · experience manager forms5 Ağu 2025

  • Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99

    adobe · flash player13 Nis 2011

  • Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %86

    adobe · flash player23 Oca 2015

  • Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to e

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %97

    adobe · acrobat reader19 Mar 2009

  • Adobe Commerce | Improper Input Validation (CWE-20)

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %95

    adobe · commerce9 Eyl 2025

  • Adobe ColdFusion Improper Access Control Arbitrary code execution

    YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %97

    adobe · coldfusion23 Mar 2023

  • Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %79

    adobe · acrobat30 Ağu 2013

  • Adobe Commerce | Incorrect Authorization (CWE-863)

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %88

    adobe · commerce11 Ağu 2026

  • Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file t

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %98

    adobe · acrobat4 Kas 2008