Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2021-28592 Adobe Illustrator JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Illustrator CWE-787 7.8 High 2021-08-20
CVE-2021-28593 Adobe Illustrator PostScript Parsing Use-After-Free Information Disclosure Vulnerability — Illustrator CWE-416 3.3 Low 2021-08-20
CVE-2021-28590 Adobe Media Encoder VOB File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Media Encoder CWE-125 3.3 Low 2021-08-20
CVE-2021-36004 Adobe InDesign CoolType out of bounds write vulnerability could lead to arbitrary stack manipulation — InDesign CWE-787 8.8 High 2021-07-27
CVE-2021-28623 Adobe Premiere Elements Privilege Escalation Vulnerability — Premiere CWE-379 6.2 - 2021-06-28
CVE-2021-28597 Adobe Photoshop Elements Privilege Escalation Vulnerability - symbolic link — Photoshop Elements CWE-379 6.2 - 2021-06-28
CVE-2021-28588 Adobe RoboHelp Server folderId Directory Traversal Remote Code Execution Vulnerability — RoboHelp Server CWE-22 8.8 High 2021-06-28
CVE-2021-28579 Adobe Connect improper access control could lead to privilege escalation — Connect CWE-284 4.3 Medium 2021-06-28
CVE-2021-21084 Adobe Experience Manager stored cross-site scripting vulnerability in resource resolver factory could lead to arbitrary code execution — Experience Manager CWE-79 7.3 High 2021-06-28
CVE-2021-28586 Adobe After Effects PDF file parsing out-of-bounds write could lead to remote code execution vulnerability — After Effects CWE-787 7.8 - 2021-06-28
CVE-2021-28574 Adobe Animate out-of-bounds read vulnerability could lead to information exposure — Animate CWE-125 4.3 Medium 2021-06-28
CVE-2021-28584 Magento Commerce path traversal vulnerability in child theme store creation — Magento Commerce CWE-22 5.4 Medium 2021-06-28
CVE-2021-28570 Adobe After Effects uncontrolled search path element vulnerability could lead to remote code execution — After Effects CWE-427 8.3 High 2021-06-28
CVE-2021-28576 Adobe Animate out-of-bounds read vulnerability could lead to information exposure — Animate CWE-125 4.3 Medium 2021-06-28
CVE-2021-28587 Adobe After Effects TIF file parsing out-of-bounds read information disclosure vulnerability — After Effects CWE-125 3.3 - 2021-06-28
CVE-2021-28585 Magento Commerce improper input validation in customer customer webapi — Magento Commerce CWE-20 5.3 Medium 2021-06-28
CVE-2021-28575 Adobe Animate out-of-bounds read vulnerability could lead to information exposure — Animate CWE-125 4.3 Medium 2021-06-28
CVE-2021-28583 Magento Commerce insecure storage of sensitive documentation — Magento Commerce CWE-657 7.5 High 2021-06-28
CVE-2021-28573 Adobe Animate out-of-bounds read vulnerability could lead to information exposure — Animate CWE-125 4.3 Medium 2021-06-28
CVE-2021-28562 Adobe Acrobat Reader use-after-free could lead to arbitrary code execution — Acrobat Reader CWE-416 8.8 High 2021-06-28
CVE-2021-21102 Adobe Illustrator DOCX file parsing directory traversal vulnerability could lead to remote code execution — Illustrator CWE-22 8.8 High 2021-06-28
CVE-2021-21090 Adobe InCopy DOCX file parsing directory traversal vulnerability could lead to remote code execution — InCopy CWE-22 8.8 High 2021-06-28
CVE-2021-28563 Magento Commerce improper Authorization via the 'Create Customer' endpoint — Magento Commerce CWE-285 6.5 Medium 2021-06-28
CVE-2021-21099 Adobe InDesign PCX file parsing out-of-bounds write vulnerability could lead to remote code execution — InDesign CWE-787 8.8 High 2021-06-28
CVE-2021-28556 Magento Commerce DOM-based cross-site scripting (XSS) could lead to arbitrary javascript execution — Magento Commerce CWE-79 6.9 Medium 2021-06-28
CVE-2021-21098 Adobe InDesign PCX file parsing out-of-bounds write vulnerability could lead to remote code execution — InDesign CWE-787 8.8 High 2021-06-28
CVE-2021-21101 Adobe Illustrator TTF font parsing out-of-bounds write vulnerability could lead to remote code execution — Illustrator CWE-787 8.8 High 2021-06-28
CVE-2021-21083 Adobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-service — Experience Manager CWE-284 7.5 High 2021-06-28
CVE-2020-10145 Adobe ColdFusion 安全漏洞 — ColdFusion CWE-284 7.8 High 2021-05-27
CVE-2021-21070 Privilege Escalation Vulnerability in Adobe RoboHelp — RoboHelp CWE-427 6.5 Medium 2021-04-19

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.