Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2024-53964 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-02-04
CVE-2024-53965 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-02-04
CVE-2025-21136 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Substance3D - Designer CWE-787 7.8 High 2025-01-14
CVE-2025-21138 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Substance3D - Designer CWE-787 7.8 High 2025-01-14
CVE-2025-21139 Substance3D - Designer | Heap-based Buffer Overflow (CWE-122) — Substance3D - Designer CWE-122 7.8 High 2025-01-14
CVE-2025-21137 Substance3D - Designer | Heap-based Buffer Overflow (CWE-122) — Substance3D - Designer CWE-122 7.8 High 2025-01-14
CVE-2025-21135 Animate | Integer Underflow (Wrap or Wraparound) (CWE-191) — Animate CWE-191 7.8 High 2025-01-14
CVE-2025-21134 Illustrator on iPad | Integer Underflow (Wrap or Wraparound) (CWE-191) — Illustrator on iPad CWE-191 7.8 High 2025-01-14
CVE-2025-21133 Illustrator on iPad | Integer Underflow (Wrap or Wraparound) (CWE-191) — Illustrator on iPad CWE-191 7.8 High 2025-01-14
CVE-2025-21132 Substance3D - Stager | Out-of-bounds Write (CWE-787) — Substance3D - Stager CWE-787 7.8 High 2025-01-14
CVE-2025-21129 Substance3D - Stager | Heap-based Buffer Overflow (CWE-122) — Substance3D - Stager CWE-122 7.8 High 2025-01-14
CVE-2025-21130 Substance3D - Stager | Out-of-bounds Write (CWE-787) — Substance3D - Stager CWE-787 7.8 High 2025-01-14
CVE-2025-21131 Substance3D - Stager | Out-of-bounds Write (CWE-787) — Substance3D - Stager CWE-787 7.8 High 2025-01-14
CVE-2025-21128 Substance3D - Stager | Stack-based Buffer Overflow (CWE-121) — Substance3D - Stager CWE-121 7.8 High 2025-01-14
CVE-2025-21122 Photoshop Desktop | Integer Underflow (Wrap or Wraparound) (CWE-191) — Photoshop Desktop CWE-191 7.8 High 2025-01-14
CVE-2025-21127 Photoshop Desktop | Uncontrolled Search Path Element (CWE-427) — Photoshop Desktop CWE-427 7.8 High 2025-01-14
CVE-2024-53961 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion CWE-22 8.1 High 2024-12-23
CVE-2023-21586 Acrobat Reader | NULL Pointer Dereference (CWE-476) — Acrobat Reader CWE-476 5.5 Medium 2024-12-18
CVE-2022-44518 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2024-12-18
CVE-2022-44517 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 5.5 Medium 2024-12-18
CVE-2022-44519 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 5.5 Medium 2024-12-18
CVE-2022-44512 Acrobat Reader | Out-of-bounds Write (CWE-787) — Acrobat Reader CWE-787 7.8 High 2024-12-18
CVE-2022-44516 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 5.5 Medium 2024-12-18
CVE-2022-44520 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2024-12-18
CVE-2022-44513 Acrobat Reader | Out-of-bounds Write (CWE-787) — Acrobat Reader CWE-787 7.8 High 2024-12-18
CVE-2022-44515 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat Reader CWE-125 5.5 Medium 2024-12-18
CVE-2022-44514 Acrobat Reader | Use After Free (CWE-416) — Acrobat Reader CWE-416 7.8 High 2024-12-18
CVE-2024-52848 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2024-12-10
CVE-2024-52865 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2024-12-10
CVE-2024-43713 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2024-12-10

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.