Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-49572 Substance3D - Modeler | Out-of-bounds Write (CWE-787) — Substance3D - Modeler CWE-787 7.8 High 2025-08-12
CVE-2025-54197 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-54186 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-54235 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-54203 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-54200 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-54204 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-49571 Substance3D - Modeler | Uncontrolled Search Path Element (CWE-427) — Substance3D - Modeler CWE-427 7.8 High 2025-08-12
CVE-2025-54202 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-54199 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-54201 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-54198 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-08-12
CVE-2025-49570 Photoshop Desktop | Out-of-bounds Write (CWE-787) — Photoshop Desktop CWE-787 7.8 High 2025-08-12
CVE-2025-49562 Animate | Use After Free (CWE-416) — Animate CWE-416 5.5 Medium 2025-08-12
CVE-2025-49561 Animate | Use After Free (CWE-416) — Animate CWE-416 7.8 High 2025-08-12
CVE-2025-49569 Substance3D - Viewer | Out-of-bounds Write (CWE-787) — Substance3D - Viewer CWE-787 7.8 High 2025-08-12
CVE-2025-49560 Substance3D - Viewer | Heap-based Buffer Overflow (CWE-122) — Substance3D - Viewer CWE-122 7.8 High 2025-08-12
CVE-2025-49556 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.5 High 2025-08-12
CVE-2025-49557 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-08-12
CVE-2025-49558 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) — Adobe Commerce CWE-367 5.9 Medium 2025-08-12
CVE-2025-49554 Adobe Commerce | Improper Input Validation (CWE-20) — Adobe Commerce CWE-20 7.5 High 2025-08-12
CVE-2025-49559 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce CWE-22 5.3 Medium 2025-08-12
CVE-2025-49555 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) — Adobe Commerce CWE-352 8.1 High 2025-08-12
CVE-2025-49563 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator CWE-787 7.8 High 2025-08-12
CVE-2025-49564 Illustrator | Stack-based Buffer Overflow (CWE-121) — Illustrator CWE-121 7.8 High 2025-08-12
CVE-2025-49568 Illustrator | Use After Free (CWE-416) — Illustrator CWE-416 5.5 Medium 2025-08-12
CVE-2025-49567 Illustrator | NULL Pointer Dereference (CWE-476) — Illustrator CWE-476 5.5 Medium 2025-08-12
CVE-2025-54253 Adobe Experience Manager | Incorrect Authorization (CWE-863) — Adobe Experience Manager CWE-863 10.0 Critical 2025-08-05
CVE-2025-54254 Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) — Adobe Experience Manager CWE-611 8.6 High 2025-08-05
CVE-2025-46958 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-08-05

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.