Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2024-53969 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-03-19
CVE-2024-53970 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-03-19
CVE-2025-21170 Substance3D - Modeler | NULL Pointer Dereference (CWE-476) — Substance3D - Modeler CWE-476 5.5 Medium 2025-03-11
CVE-2025-27181 Substance3D - Modeler | Use After Free (CWE-416) — Substance3D - Modeler CWE-416 7.8 High 2025-03-11
CVE-2025-27180 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2025-03-11
CVE-2025-27173 Substance3D - Modeler | Heap-based Buffer Overflow (CWE-122) — Substance3D - Modeler CWE-122 7.8 High 2025-03-11
CVE-2025-24431 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 5.5 Medium 2025-03-11
CVE-2025-27158 Acrobat Reader | Access of Uninitialized Pointer (CWE-824) — Acrobat Reader CWE-824 7.8 High 2025-03-11
CVE-2025-27161 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 7.8 High 2025-03-11
CVE-2025-27164 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 5.5 Medium 2025-03-11
CVE-2025-27174 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2025-03-11
CVE-2025-27162 Acrobat Reader | Access of Uninitialized Pointer (CWE-824) — Acrobat Reader CWE-824 7.8 High 2025-03-11
CVE-2025-27160 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2025-03-11
CVE-2025-27159 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2025-03-11
CVE-2025-27163 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 5.5 Medium 2025-03-11
CVE-2025-27169 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator CWE-787 7.8 High 2025-03-11
CVE-2025-27167 Illustrator | Untrusted Search Path (CWE-426) — Illustrator CWE-426 7.8 High 2025-03-11
CVE-2025-27168 Illustrator | Stack-based Buffer Overflow (CWE-121) — Illustrator CWE-121 7.8 High 2025-03-11
CVE-2025-27170 Illustrator | NULL Pointer Dereference (CWE-476) — Illustrator CWE-476 5.5 Medium 2025-03-11
CVE-2025-24449 Illustrator | Out-of-bounds Read (CWE-125) — Illustrator CWE-125 5.5 Medium 2025-03-11
CVE-2025-24448 Illustrator | Out-of-bounds Read (CWE-125) — Illustrator CWE-125 5.5 Medium 2025-03-11
CVE-2025-27166 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-03-11
CVE-2025-27175 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-03-11
CVE-2025-27177 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-03-11
CVE-2025-27178 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-03-11
CVE-2025-27176 InDesign Desktop | NULL Pointer Dereference (CWE-476) — InDesign Desktop CWE-476 5.5 Medium 2025-03-11
CVE-2025-24453 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-03-11
CVE-2025-24452 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-03-11
CVE-2025-27171 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-03-11
CVE-2025-27179 InDesign Desktop | NULL Pointer Dereference (CWE-476) — InDesign Desktop CWE-476 5.5 Medium 2025-03-11

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.