Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-30322 Substance3D - Painter | Out-of-bounds Write (CWE-787) — Substance3D - Painter CWE-787 7.8 High 2025-05-13
CVE-2025-27197 Lightroom Desktop | Out-of-bounds Write (CWE-787) — Lightroom Desktop CWE-787 7.8 High 2025-05-13
CVE-2025-30320 InDesign Desktop | NULL Pointer Dereference (CWE-476) — InDesign Desktop CWE-476 5.5 Medium 2025-05-13
CVE-2025-30318 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-05-13
CVE-2025-30319 InDesign Desktop | NULL Pointer Dereference (CWE-476) — InDesign Desktop CWE-476 5.5 Medium 2025-05-13
CVE-2025-30310 Dreamweaver Desktop | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843) — Dreamweaver Desktop CWE-843 7.8 High 2025-05-13
CVE-2025-27190 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 5.3 Medium 2025-04-08
CVE-2025-27191 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 5.3 Medium 2025-04-08
CVE-2025-27192 Adobe Commerce | Insufficiently Protected Credentials (CWE-522) — Adobe Commerce CWE-522 2.7 Low 2025-04-08
CVE-2025-27188 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2025-04-08
CVE-2025-27189 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) — Adobe Commerce CWE-352 4.3 Medium 2025-04-08
CVE-2025-30287 ColdFusion | Improper Authentication (CWE-287) — ColdFusion CWE-287 8.2 High 2025-04-08
CVE-2025-30293 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion CWE-20 6.8 Medium 2025-04-08
CVE-2025-30292 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) — ColdFusion CWE-79 6.1 Medium 2025-04-08
CVE-2025-30290 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion CWE-22 8.7 High 2025-04-08
CVE-2025-30282 ColdFusion | Improper Authentication (CWE-287) — ColdFusion CWE-287 9.1 Critical 2025-04-08
CVE-2025-30284 ColdFusion | Deserialization of Untrusted Data (CWE-502) — ColdFusion CWE-502 8.4 High 2025-04-08
CVE-2025-30294 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion CWE-20 6.8 Medium 2025-04-08
CVE-2025-30289 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — ColdFusion CWE-78 8.2 High 2025-04-08
CVE-2025-30288 ColdFusion | Improper Access Control (CWE-284) — ColdFusion CWE-284 8.2 High 2025-04-08
CVE-2025-24446 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion CWE-20 9.1 Critical 2025-04-08
CVE-2025-24447 ColdFusion | Deserialization of Untrusted Data (CWE-502) — ColdFusion CWE-502 9.1 Critical 2025-04-08
CVE-2025-30281 ColdFusion | Improper Access Control (CWE-284) — ColdFusion CWE-284 9.1 Critical 2025-04-08
CVE-2025-30291 ColdFusion | Information Exposure (CWE-200) — ColdFusion CWE-200 5.5 Medium 2025-04-08
CVE-2025-30285 ColdFusion | Deserialization of Untrusted Data (CWE-502) — ColdFusion CWE-502 8.4 High 2025-04-08
CVE-2025-30286 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — ColdFusion CWE-78 8.4 High 2025-04-08
CVE-2025-30307 XMPWorker | Out-of-bounds Read (CWE-125) — XMPWorker CWE-125 5.5 Medium 2025-04-08
CVE-2025-30308 XMPWorker | Out-of-bounds Read (CWE-125) — XMPWorker CWE-125 5.5 Medium 2025-04-08
CVE-2025-30305 XMPWorker | Out-of-bounds Read (CWE-125) — XMPWorker CWE-125 5.5 Medium 2025-04-08
CVE-2025-30306 XMPWorker | Out-of-bounds Read (CWE-125) — XMPWorker CWE-125 5.5 Medium 2025-04-08

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.