Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

Found 65 results / 4862 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-48327 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 9.0 Critical 2026-07-14
CVE-2026-48329 ColdFusion | Insufficient Session Expiration (CWE-613) — ColdFusion 2025 CWE-613 2.7 Low 2026-07-14
CVE-2026-48321 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 9.3 Critical 2026-07-14
CVE-2026-48319 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 9.1 Critical 2026-07-14
CVE-2026-48322 ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94) — ColdFusion 2025 CWE-94 9.9 Critical 2026-07-14
CVE-2026-48284 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 9.6 Critical 2026-07-14
CVE-2026-48328 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 7.7 High 2026-07-14
CVE-2026-48325 ColdFusion | Missing Authentication for Critical Function (CWE-306) — ColdFusion 2025 CWE-306 9.3 Critical 2026-07-14
CVE-2026-48363 ColdFusion | Uncontrolled Search Path Element (CWE-427) — ColdFusion 2025 CWE-427 8.2 High 2026-07-13
CVE-2026-48364 ColdFusion | Uncontrolled Search Path Element (CWE-427) — ColdFusion 2025 CWE-427 8.2 High 2026-07-13
CVE-2026-48316 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 10.0 Critical 2026-07-06
CVE-2026-48315 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 9.3 Critical 2026-06-30
CVE-2026-48277 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 10.0 Critical 2026-06-30
CVE-2026-48281 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 10.0 Critical 2026-06-30
CVE-2026-48285 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) — ColdFusion 2025 CWE-918 8.6 High 2026-06-30
CVE-2026-48313 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 9.3 Critical 2026-06-30
CVE-2026-48307 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) — ColdFusion 2025 CWE-79 8.8 High 2026-06-30
CVE-2026-48314 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 6.5 Medium 2026-06-30
CVE-2026-48276 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) — ColdFusion 2025 CWE-434 10.0 Critical 2026-06-30
CVE-2026-48282 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 10.0 Critical 2026-06-30
CVE-2026-48283 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) — ColdFusion 2025 CWE-434 10.0 Critical 2026-06-30
CVE-2026-47929 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 8.4 High 2026-06-09
CVE-2026-47932 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 8.8 High 2026-06-09
CVE-2026-47960 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) — ColdFusion 2025 CWE-611 7.4 High 2026-06-09
CVE-2026-47928 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 9.6 Critical 2026-06-09
CVE-2026-47931 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 8.4 High 2026-06-09
CVE-2026-47930 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 8.1 High 2026-06-09
CVE-2026-47933 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusion 2025 CWE-79 4.8 Medium 2026-06-09
CVE-2026-34619 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 7.7 High 2026-04-14
CVE-2026-27308 ColdFusion | Uncontrolled Resource Consumption (CWE-400) — ColdFusion 2025 CWE-400 2.4 Low 2026-04-14

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.