Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-43564 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion CWE-863 9.1 Critical 2025-05-13
CVE-2025-43560 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion CWE-20 9.1 Critical 2025-05-13
CVE-2025-43563 ColdFusion | Improper Access Control (CWE-284) — ColdFusion CWE-284 9.1 Critical 2025-05-13
CVE-2025-43561 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion CWE-863 9.1 Critical 2025-05-13
CVE-2025-30315 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Connect CWE-79 6.1 Medium 2025-05-13
CVE-2025-30316 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Connect CWE-79 5.4 Medium 2025-05-13
CVE-2025-30314 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Connect CWE-79 6.1 Medium 2025-05-13
CVE-2025-43567 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Connect CWE-79 9.3 Critical 2025-05-13
CVE-2025-43554 Substance3D - Modeler | Out-of-bounds Write (CWE-787) — Substance3D - Modeler CWE-787 7.8 High 2025-05-13
CVE-2025-43553 Substance3D - Modeler | Uncontrolled Search Path Element (CWE-427) — Substance3D - Modeler CWE-427 7.8 High 2025-05-13
CVE-2025-43569 Substance3D - Stager | Out-of-bounds Write (CWE-787) — Substance3D - Stager CWE-787 7.8 High 2025-05-13
CVE-2025-43571 Substance3D - Stager | Use After Free (CWE-416) — Substance3D - Stager CWE-416 7.8 High 2025-05-13
CVE-2025-43570 Substance3D - Stager | Use After Free (CWE-416) — Substance3D - Stager CWE-416 7.8 High 2025-05-13
CVE-2025-43551 Substance3D - Stager | Out-of-bounds Read (CWE-125) — Substance3D - Stager CWE-125 5.5 Medium 2025-05-13
CVE-2025-43568 Substance3D - Stager | Use After Free (CWE-416) — Substance3D - Stager CWE-416 7.8 High 2025-05-13
CVE-2025-43549 Substance3D - Stager | Use After Free (CWE-416) — Substance3D - Stager CWE-416 7.8 High 2025-05-13
CVE-2025-43572 Dimension | Out-of-bounds Write (CWE-787) — Dimension CWE-787 7.8 High 2025-05-13
CVE-2025-43548 Dimension | Out-of-bounds Write (CWE-787) — Dimension CWE-787 7.8 High 2025-05-13
CVE-2025-43547 Bridge | Integer Overflow or Wraparound (CWE-190) — Bridge CWE-190 7.8 High 2025-05-13
CVE-2025-43546 Bridge | Integer Underflow (Wrap or Wraparound) (CWE-191) — Bridge CWE-191 7.8 High 2025-05-13
CVE-2025-43545 Bridge | Access of Uninitialized Pointer (CWE-824) — Bridge CWE-824 7.8 High 2025-05-13
CVE-2025-30330 Illustrator | Heap-based Buffer Overflow (CWE-122) — Illustrator CWE-122 7.8 High 2025-05-13
CVE-2025-30329 Animate | NULL Pointer Dereference (CWE-476) — Animate CWE-476 5.5 Medium 2025-05-13
CVE-2025-43557 Animate | Access of Uninitialized Pointer (CWE-824) — Animate CWE-824 7.8 High 2025-05-13
CVE-2025-43556 Animate | Integer Overflow or Wraparound (CWE-190) — Animate CWE-190 7.8 High 2025-05-13
CVE-2025-43555 Animate | Integer Underflow (Wrap or Wraparound) (CWE-191) — Animate CWE-191 7.8 High 2025-05-13
CVE-2025-30328 Animate | Out-of-bounds Write (CWE-787) — Animate CWE-787 7.8 High 2025-05-13
CVE-2025-30325 Photoshop Desktop | Integer Overflow or Wraparound (CWE-190) — Photoshop Desktop CWE-190 7.8 High 2025-05-13
CVE-2025-30326 Photoshop Desktop | Access of Uninitialized Pointer (CWE-824) — Photoshop Desktop CWE-824 7.8 High 2025-05-13
CVE-2025-30324 Photoshop Desktop | Integer Underflow (Wrap or Wraparound) (CWE-191) — Photoshop Desktop CWE-191 7.8 High 2025-05-13

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.