Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-43550 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2025-06-10
CVE-2025-43577 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2025-06-10
CVE-2025-47112 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 5.5 Medium 2025-06-10
CVE-2025-43575 Acrobat Reader | Out-of-bounds Write (CWE-787) — Acrobat Reader CWE-787 7.8 High 2025-06-10
CVE-2025-43574 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2025-06-10
CVE-2025-43578 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 5.5 Medium 2025-06-10
CVE-2025-43576 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2025-06-10
CVE-2025-47107 InCopy | Heap-based Buffer Overflow (CWE-122) — InCopy CWE-122 7.8 High 2025-06-10
CVE-2025-30327 InCopy | Integer Overflow or Wraparound (CWE-190) — InCopy CWE-190 7.8 High 2025-06-10
CVE-2025-43581 Substance3D - Sampler | Out-of-bounds Write (CWE-787) — Substance3D - Sampler CWE-787 7.8 High 2025-06-10
CVE-2025-43588 Substance3D - Sampler | Out-of-bounds Write (CWE-787) — Substance3D - Sampler CWE-787 7.8 High 2025-06-10
CVE-2025-47108 Substance3D - Painter | Out-of-bounds Write (CWE-787) — Substance3D - Painter CWE-787 7.8 High 2025-06-10
CVE-2025-30321 InDesign Desktop | NULL Pointer Dereference (CWE-476) — InDesign Desktop CWE-476 5.5 Medium 2025-06-10
CVE-2025-43589 InDesign Desktop | Use After Free (CWE-416) — InDesign Desktop CWE-416 7.8 High 2025-06-10
CVE-2025-43558 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-06-10
CVE-2025-30317 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-06-10
CVE-2025-47105 InDesign Desktop | Out-of-bounds Read (CWE-125) — InDesign Desktop CWE-125 5.5 Medium 2025-06-10
CVE-2025-47104 InDesign Desktop | Out-of-bounds Read (CWE-125) — InDesign Desktop CWE-125 5.5 Medium 2025-06-10
CVE-2025-43593 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-06-10
CVE-2025-47106 InDesign Desktop | Use After Free (CWE-416) — InDesign Desktop CWE-416 5.5 Medium 2025-06-10
CVE-2025-43590 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-06-10
CVE-2025-27206 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 5.3 Medium 2025-06-10
CVE-2025-47110 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.4 High 2025-06-10
CVE-2025-43586 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 8.1 High 2025-06-10
CVE-2025-27207 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 6.5 Medium 2025-06-10
CVE-2025-43585 Adobe Commerce | Improper Authorization (CWE-285) — Adobe Commerce CWE-285 8.2 High 2025-06-10
CVE-2025-43559 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion CWE-20 9.1 Critical 2025-05-13
CVE-2025-43565 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion CWE-863 8.4 High 2025-05-13
CVE-2025-43562 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — ColdFusion CWE-78 9.1 Critical 2025-05-13
CVE-2025-43566 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion CWE-22 6.8 Medium 2025-05-13

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.