Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2025-24418 Adobe Commerce | Improper Authorization (CWE-285) — Adobe Commerce CWE-285 8.1 High 2025-02-11
CVE-2025-24417 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-02-11
CVE-2025-24406 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce CWE-22 7.5 High 2025-02-11
CVE-2025-24409 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 8.2 High 2025-02-11
CVE-2025-24425 Adobe Commerce | Business Logic Errors (CWE-840) — Adobe Commerce CWE-840 5.3 Medium 2025-02-11
CVE-2025-24421 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2025-02-11
CVE-2025-24412 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-02-11
CVE-2025-24427 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 6.5 Medium 2025-02-11
CVE-2025-24426 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 6.5 Medium 2025-02-11
CVE-2025-24428 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 5.4 Medium 2025-02-11
CVE-2025-24410 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2025-02-11
CVE-2025-24408 Adobe Commerce | Information Exposure (CWE-200) — Adobe Commerce CWE-200 6.5 Medium 2025-02-11
CVE-2025-24435 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 4.3 Medium 2025-02-11
CVE-2025-21162 Photoshop Elements | Creation of Temporary File in Directory with Incorrect Permissions (CWE-379) — Photoshop Elements CWE-379 5.5 Medium 2025-02-11
CVE-2025-21161 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Substance3D - Designer CWE-787 7.8 High 2025-02-11
CVE-2025-21160 Illustrator | Integer Underflow (Wrap or Wraparound) (CWE-191) — Illustrator CWE-191 7.8 High 2025-02-11
CVE-2025-21159 Illustrator | Use After Free (CWE-416) — Illustrator CWE-416 7.8 High 2025-02-11
CVE-2025-21163 Illustrator | Stack-based Buffer Overflow (CWE-121) — Illustrator CWE-121 7.8 High 2025-02-11
CVE-2025-21156 InCopy | Integer Underflow (Wrap or Wraparound) (CWE-191) — InCopy CWE-191 7.8 High 2025-02-11
CVE-2025-21155 Substance3D - Stager | NULL Pointer Dereference (CWE-476) — Substance3D - Stager CWE-476 5.5 Medium 2025-02-11
CVE-2025-21126 InDesign Desktop | Improper Input Validation (CWE-20) — InDesign Desktop CWE-20 5.5 Medium 2025-02-11
CVE-2025-21158 InDesign Desktop | Integer Underflow (Wrap or Wraparound) (CWE-191) — InDesign Desktop CWE-191 7.8 High 2025-02-11
CVE-2025-21125 InDesign Desktop | NULL Pointer Dereference (CWE-476) — InDesign Desktop CWE-476 5.5 Medium 2025-02-11
CVE-2025-21123 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2025-02-11
CVE-2025-21157 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-02-11
CVE-2025-21124 InDesign Desktop | Out-of-bounds Read (CWE-125) — InDesign Desktop CWE-125 5.5 Medium 2025-02-11
CVE-2025-21121 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2025-02-11
CVE-2024-53962 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-02-04
CVE-2024-53963 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-02-04
CVE-2024-53966 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-02-04

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.