Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-49525 Illustrator | Out-of-bounds Read (CWE-125) — Illustrator CWE-125 5.5 Medium 2025-07-08
CVE-2025-49530 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator CWE-787 7.8 High 2025-07-08
CVE-2025-30313 Illustrator | Out-of-bounds Read (CWE-125) — Illustrator CWE-125 5.5 Medium 2025-07-08
CVE-2025-49526 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator CWE-787 7.8 High 2025-07-08
CVE-2025-43591 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-07-08
CVE-2025-43592 InDesign Desktop | Access of Uninitialized Pointer (CWE-824) — InDesign Desktop CWE-824 7.8 High 2025-07-08
CVE-2025-43594 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-07-08
CVE-2025-47134 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-07-08
CVE-2025-47136 InDesign Desktop | Integer Underflow (Wrap or Wraparound) (CWE-191) — InDesign Desktop CWE-191 7.8 High 2025-07-08
CVE-2025-47103 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-07-08
CVE-2025-49547 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-07-08
CVE-2025-49534 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-07-08
CVE-2025-49533 Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502) — Adobe Experience Manager (MS) CWE-502 9.8 Critical 2025-07-08
CVE-2025-27203 Adobe Connect | Deserialization of Untrusted Data (CWE-502) — Adobe Connect CWE-502 9.6 Critical 2025-07-08
CVE-2025-27165 Substance3D - Stager | Out-of-bounds Read (CWE-125) — Substance3D - Stager CWE-125 5.5 Medium 2025-07-08
CVE-2025-43584 Substance3D - Viewer | Out-of-bounds Read (CWE-125) — Substance3D - Viewer CWE-125 5.5 Medium 2025-07-08
CVE-2025-43582 Substance3D - Viewer | Heap-based Buffer Overflow (CWE-122) — Substance3D - Viewer CWE-122 7.8 High 2025-07-08
CVE-2025-43583 Substance3D - Viewer | NULL Pointer Dereference (CWE-476) — Substance3D - Viewer CWE-476 5.5 Medium 2025-07-08
CVE-2025-49535 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) — ColdFusion CWE-611 9.3 Critical 2025-07-08
CVE-2025-49542 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) — ColdFusion CWE-79 5.2 Medium 2025-07-08
CVE-2025-49536 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion CWE-863 7.3 High 2025-07-08
CVE-2025-49539 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) — ColdFusion CWE-611 4.5 Medium 2025-07-08
CVE-2025-49545 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) — ColdFusion CWE-918 6.2 Medium 2025-07-08
CVE-2025-49541 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusion CWE-79 4.3 Medium 2025-07-08
CVE-2025-49537 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — ColdFusion CWE-78 7.9 High 2025-07-08
CVE-2025-49551 ColdFusion | Use of Hard-coded Credentials (CWE-798) — ColdFusion CWE-798 8.8 High 2025-07-08
CVE-2025-49546 ColdFusion | Improper Access Control (CWE-284) — ColdFusion CWE-284 2.4 Low 2025-07-08
CVE-2025-49544 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) — ColdFusion CWE-611 6.8 Medium 2025-07-08
CVE-2025-49543 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusion CWE-79 4.3 Medium 2025-07-08
CVE-2025-49540 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusion CWE-79 4.3 Medium 2025-07-08

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.