Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2021-36063 Adobe Connect Reflected Cross-site Scripting via 'isTabletDeviceHTML' parameter — Connect CWE-79 5.4 Medium 2021-09-01
CVE-2021-36066 Adobe Photoshop U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Photoshop CWE-787 7.8 High 2021-09-01
CVE-2021-36068 Adobe Bridge Memory Corruption Vulnerability Could Lead to Arbitrary Code Execution — Bridge CWE-788 7.8 High 2021-09-01
CVE-2021-36058 XMP Toolkit SDK Integer Overflow Vulnerability Could Result In Application Denial Of Service — XMP Toolkit CWE-190 5.5 Medium 2021-09-01
CVE-2021-36061 Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordings — Connect CWE-657 5.4 Medium 2021-09-01
CVE-2021-36064 XMP Toolkit SDK SVG_Adapter ParseFullNS Buffer Underflow — XMP Toolkit CWE-124 7.8 High 2021-09-01
CVE-2021-36056 XMP Toolkit SDK Heap-based Buffer Overflow Could Lead To Arbitrary Code Execution — XMP Toolkit CWE-122 5.5 Medium 2021-09-01
CVE-2021-36062 Adobe Connect Reflected Cross-site Scripting via 'campaign-id' parameter — Connect CWE-79 5.4 Medium 2021-09-01
CVE-2021-36054 XMP Toolkit SDK Heap-based Buffer Overflow in the PSD_MetaHandler::CacheFileData Could Lead To Application Denial Of Service — XMP Toolkit CWE-122 3.3 Low 2021-09-01
CVE-2021-36059 Adobe Bridge Memory Corruption Vulnerability Could Lead to Arbitrary Code Execution — Bridge CWE-788 7.8 High 2021-09-01
CVE-2021-36057 XMP Toolkit SDK Write-What-Where Condition Could Lead To Local Application Denial Of Service — XMP Toolkit CWE-123 3.3 - 2021-09-01
CVE-2021-36055 XMP Toolkit SDK Use After Free Vulnerability In ReadingXMPNewDOM Could Lead To Arbitrary Code Execution — XMP Toolkit CWE-416 7.8 High 2021-09-01
CVE-2021-36052 XMPToolkit SDK ImportTIFF_CheckStandardMapping Memory Corruption — XMP Toolkit CWE-788 7.8 High 2021-09-01
CVE-2021-36053 XMP Toolkit SDK Out-of-bounds Read Vulnerability In FindAndReadXMPChunk Could Lead To Information Exposure — XMP Toolkit CWE-125 3.3 Low 2021-09-01
CVE-2021-36050 XMP Toolkit SDK Heap-based Buffer Overflow Could Lead To Arbitrary Code Execution — XMP Toolkit CWE-122 7.8 - 2021-09-01
CVE-2021-36044 Magento Commerce GraphQL Improper Input Validation Could Lead To Denial Of Service — Magento Commerce CWE-20 7.5 High 2021-09-01
CVE-2021-36048 XMP Toolkit SDK Improper Input Validation Could Lead To Arbitrary Code Execution — XMP Toolkit CWE-20 7.8 High 2021-09-01
CVE-2021-36047 XMP Toolkit SDK Improper Input Validation Could Lead To Arbitrary Code Execution — XMP Toolkit CWE-20 7.8 High 2021-09-01
CVE-2021-36049 Adobe Bridge Memory Corruption Vulnerability Could Lead to Arbitrary Code Execution — Bridge CWE-788 7.8 High 2021-09-01
CVE-2021-36045 XMP Toolkit SDK Out-of-bounds Read Vulnerability In PostScriptSupport::ConvertToDate Could Lead To Information Exposure — XMP Toolkit CWE-125 3.3 Low 2021-09-01
CVE-2021-36027 Magento Commerce Stored Cross-site Scripting Vulnerability — Magento Commerce CWE-79 6.5 Medium 2021-09-01
CVE-2021-36043 Magento Commerce Authenticated Blind SSRF Could Lead To Remote Code Execution — Magento Commerce CWE-918 8.0 High 2021-09-01
CVE-2021-36046 XMP Toolkit SDK TIFF_MemoryReader::SortIFD function Memory Corruption — XMP Toolkit CWE-788 7.8 - 2021-09-01
CVE-2021-36042 Magento Commerce API File Option Upload Extension Improper Input Validation Vulnerability Could Lead To Remote Code Execution — Magento Commerce CWE-20 9.1 Critical 2021-09-01
CVE-2021-36030 Magento Commerce Improper Input Validation During Checkout Process Could Lead To Privilege Escalation — Magento Commerce CWE-20 7.5 High 2021-09-01
CVE-2021-36041 Magento Commerce Improper Input Validation Could Lead To Remote Code Execution — Magento Commerce CWE-20 9.1 Critical 2021-09-01
CVE-2021-36040 Magento Commerce Improper Input Validation Could Lead To Remote Code Execution — Magento Commerce CWE-20 9.1 Critical 2021-09-01
CVE-2021-36025 Magento Commerce Customer Edition Improper Input Validation Could Lead To Remote Code Execution — Magento Commerce CWE-20 9.1 Critical 2021-09-01
CVE-2021-36020 Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution — Magento Commerce CWE-91 8.2 High 2021-09-01
CVE-2021-36035 Magento Commerce Stock Media Improper Input Validation Could Lead To Remote Code Execution — Magento Commerce CWE-20 9.1 Critical 2021-09-01

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.