Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-64897 ColdFusion | Improper Access Control (CWE-284) — ColdFusion CWE-284 5.6 Medium 2025-12-09
CVE-2025-61823 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) — ColdFusion CWE-611 6.2 Medium 2025-12-09
CVE-2025-61811 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion CWE-22 9.1 Critical 2025-12-09
CVE-2025-64896 Creative Cloud Desktop | Creation of Temporary File in Directory with Incorrect Permissions (CWE-379) — Creative Cloud Desktop CWE-379 5.5 Medium 2025-12-09
CVE-2025-64899 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 7.8 High 2025-12-09
CVE-2025-64785 Acrobat Reader | Untrusted Search Path (CWE-426) — Acrobat Reader CWE-426 7.8 High 2025-12-09
CVE-2025-64786 Acrobat Reader | Improper Verification of Cryptographic Signature (CWE-347) — Acrobat Reader CWE-347 3.3 Low 2025-12-09
CVE-2025-64787 Acrobat Reader | Improper Verification of Cryptographic Signature (CWE-347) — Acrobat Reader CWE-347 3.3 Low 2025-12-09
CVE-2025-64784 DNG SDK | Heap-based Buffer Overflow (CWE-122) — DNG SDK CWE-122 7.1 High 2025-12-09
CVE-2025-64894 DNG SDK | Integer Overflow or Wraparound (CWE-190) — DNG SDK CWE-190 5.5 Medium 2025-12-09
CVE-2025-64893 DNG SDK | Out-of-bounds Read (CWE-125) — DNG SDK CWE-125 7.1 High 2025-12-09
CVE-2025-64783 DNG SDK | Integer Overflow or Wraparound (CWE-190) — DNG SDK CWE-190 7.8 High 2025-12-09
CVE-2025-61835 Substance3D - Stager | Integer Underflow (Wrap or Wraparound) (CWE-191) — Substance3D - Stager CWE-191 7.8 High 2025-11-11
CVE-2025-61833 Substance3D - Stager | Out-of-bounds Read (CWE-125) — Substance3D - Stager CWE-125 7.8 High 2025-11-11
CVE-2025-64531 Substance3D - Stager | Use After Free (CWE-416) — Substance3D - Stager CWE-416 7.8 High 2025-11-11
CVE-2025-61834 Substance3D - Stager | Use After Free (CWE-416) — Substance3D - Stager CWE-416 7.8 High 2025-11-11
CVE-2025-61843 Format Plugins | Out-of-bounds Read (CWE-125) — Format Plugins CWE-125 5.5 Medium 2025-11-11
CVE-2025-61839 Format Plugins | Out-of-bounds Read (CWE-125) — Format Plugins CWE-125 7.8 High 2025-11-11
CVE-2025-61840 Format Plugins | Out-of-bounds Read (CWE-125) — Format Plugins CWE-125 5.5 Medium 2025-11-11
CVE-2025-61845 Format Plugins | Out-of-bounds Read (CWE-125) — Format Plugins CWE-125 5.5 Medium 2025-11-11
CVE-2025-61837 Format Plugins | Heap-based Buffer Overflow (CWE-122) — Format Plugins CWE-122 7.8 High 2025-11-11
CVE-2025-61838 Format Plugins | Heap-based Buffer Overflow (CWE-122) — Format Plugins CWE-122 7.8 High 2025-11-11
CVE-2025-61841 Format Plugins | Out-of-bounds Read (CWE-125) — Format Plugins CWE-125 5.5 Medium 2025-11-11
CVE-2025-61844 Format Plugins | Out-of-bounds Read (CWE-125) — Format Plugins CWE-125 5.5 Medium 2025-11-11
CVE-2025-61842 Format Plugins | Use After Free (CWE-416) — Format Plugins CWE-416 5.5 Medium 2025-11-11
CVE-2025-61830 Adobe Pass | Incorrect Authorization (CWE-863) — Adobe Pass CWE-863 7.1 High 2025-11-11
CVE-2025-61828 Illustrator on iPad | Out-of-bounds Write (CWE-787) — Illustrator on iPad CWE-787 7.8 High 2025-11-11
CVE-2025-61827 Illustrator on iPad | Heap-based Buffer Overflow (CWE-122) — Illustrator on iPad CWE-122 7.8 High 2025-11-11
CVE-2025-61826 Illustrator on iPad | Integer Underflow (Wrap or Wraparound) (CWE-191) — Illustrator on iPad CWE-191 7.8 High 2025-11-11
CVE-2025-61829 Illustrator on iPad | Heap-based Buffer Overflow (CWE-122) — Illustrator on iPad CWE-122 7.8 High 2025-11-11

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.