Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-61836 Illustrator on iPad | Integer Underflow (Wrap or Wraparound) (CWE-191) — Illustrator on iPad CWE-191 7.8 High 2025-11-11
CVE-2025-61831 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator CWE-787 7.8 High 2025-11-11
CVE-2025-61820 Illustrator | Heap-based Buffer Overflow (CWE-122) — Illustrator CWE-122 7.8 High 2025-11-11
CVE-2025-61819 Photoshop Desktop | Heap-based Buffer Overflow (CWE-122) — Photoshop Desktop CWE-122 7.8 High 2025-11-11
CVE-2025-61818 InCopy | Use After Free (CWE-416) — InCopy CWE-416 7.8 High 2025-11-11
CVE-2025-61816 InCopy | Heap-based Buffer Overflow (CWE-122) — InCopy CWE-122 7.8 High 2025-11-11
CVE-2025-61817 InCopy | Use After Free (CWE-416) — InCopy CWE-416 7.8 High 2025-11-11
CVE-2025-61815 InDesign Desktop | Use After Free (CWE-416) — InDesign Desktop CWE-416 7.8 High 2025-11-11
CVE-2025-61814 InDesign Desktop | Use After Free (CWE-416) — InDesign Desktop CWE-416 7.8 High 2025-11-11
CVE-2025-61824 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-11-11
CVE-2025-61832 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-11-11
CVE-2025-54271 Creative Cloud Desktop | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) — Creative Cloud Desktop CWE-367 5.6 Medium 2025-10-15
CVE-2025-54268 Bridge | Heap-based Buffer Overflow (CWE-122) — Bridge CWE-122 7.8 High 2025-10-15
CVE-2025-54278 Bridge | Heap-based Buffer Overflow (CWE-122) — Bridge CWE-122 5.5 Medium 2025-10-15
CVE-2025-61804 Animate | Heap-based Buffer Overflow (CWE-122) — Animate CWE-122 7.8 High 2025-10-15
CVE-2025-54279 Animate | Use After Free (CWE-416) — Animate CWE-416 7.8 High 2025-10-15
CVE-2025-54269 Animate | Out-of-bounds Read (CWE-125) — Animate CWE-125 5.5 Medium 2025-10-15
CVE-2025-54270 Animate | NULL Pointer Dereference (CWE-476) — Animate CWE-476 5.5 Medium 2025-10-15
CVE-2025-49552 Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Connect CWE-79 8.1 High 2025-10-14
CVE-2025-49553 Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Connect CWE-79 9.3 Critical 2025-10-14
CVE-2025-54196 Adobe Connect | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) — Adobe Connect CWE-601 4.3 Medium 2025-10-14
CVE-2025-61797 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-10-14
CVE-2025-54272 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-10-14
CVE-2025-61796 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-10-14
CVE-2025-54267 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 6.5 Medium 2025-10-14
CVE-2025-54266 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 4.8 Medium 2025-10-14
CVE-2025-54263 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 8.1 High 2025-10-14
CVE-2025-54264 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.1 High 2025-10-14
CVE-2025-54265 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 5.9 Medium 2025-10-14
CVE-2025-61803 Substance3D - Stager | Integer Overflow or Wraparound (CWE-190) — Substance3D - Stager CWE-190 7.8 High 2025-10-14

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.