Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-24444 Substance3D - Sampler | Out-of-bounds Write (CWE-787) — Substance3D - Sampler CWE-787 7.8 High 2025-03-11
CVE-2025-24443 Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122) — Substance3D - Sampler CWE-122 7.8 High 2025-03-11
CVE-2025-24441 Substance3D - Sampler | Out-of-bounds Write (CWE-787) — Substance3D - Sampler CWE-787 7.8 High 2025-03-11
CVE-2025-24445 Substance3D - Sampler | Out-of-bounds Write (CWE-787) — Substance3D - Sampler CWE-787 7.8 High 2025-03-11
CVE-2025-24439 Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122) — Substance3D - Sampler CWE-122 7.8 High 2025-03-11
CVE-2025-24442 Substance3D - Sampler | Out-of-bounds Write (CWE-787) — Substance3D - Sampler CWE-787 7.8 High 2025-03-11
CVE-2025-24440 Substance3D - Sampler | Out-of-bounds Write (CWE-787) — Substance3D - Sampler CWE-787 7.8 High 2025-03-11
CVE-2025-24451 Substance3D - Painter | Out-of-bounds Write (CWE-787) — Substance3D - Painter CWE-787 7.8 High 2025-03-11
CVE-2025-24450 Substance3D - Painter | Out-of-bounds Write (CWE-787) — Substance3D - Painter CWE-787 7.8 High 2025-03-11
CVE-2025-27172 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Substance3D - Designer CWE-787 7.8 High 2025-03-11
CVE-2025-21169 Substance3D - Designer | Heap-based Buffer Overflow (CWE-122) — Substance3D - Designer CWE-122 7.8 High 2025-03-11
CVE-2024-53974 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-02-19
CVE-2025-24422 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 6.5 Medium 2025-02-11
CVE-2025-24414 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-02-11
CVE-2025-24434 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 9.1 Critical 2025-02-11
CVE-2025-24437 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 5.4 Medium 2025-02-11
CVE-2025-24415 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-02-11
CVE-2025-24411 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 8.1 High 2025-02-11
CVE-2025-24416 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-02-11
CVE-2025-24420 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2025-02-11
CVE-2025-24413 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-02-11
CVE-2025-24419 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2025-02-11
CVE-2025-24432 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) — Adobe Commerce CWE-367 3.7 Low 2025-02-11
CVE-2025-24424 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 6.5 Medium 2025-02-11
CVE-2025-24430 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) — Adobe Commerce CWE-367 3.7 Low 2025-02-11
CVE-2025-24429 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 3.5 Low 2025-02-11
CVE-2025-24436 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2025-02-11
CVE-2025-24407 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.1 High 2025-02-11
CVE-2025-24438 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-02-11
CVE-2025-24423 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 4.3 Medium 2025-02-11

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.