Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2024-49521 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Commerce CWE-918 7.7 High 2024-11-12
CVE-2024-49527 Animate | Out-of-bounds Read (CWE-125) — Animate CWE-125 5.5 Medium 2024-11-12
CVE-2024-49528 Animate | Out-of-bounds Write (CWE-787) — Animate CWE-787 7.8 High 2024-11-12
CVE-2024-49526 Animate | Use After Free (CWE-416) — Animate CWE-416 7.8 High 2024-11-12
CVE-2024-49523 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2024-11-07
CVE-2024-49524 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2024-11-07
CVE-2024-49522 Substance3D - Painter | Out-of-bounds Write (CWE-787) — Substance3D - Painter CWE-787 7.8 High 2024-11-05
CVE-2024-47459 Substance3D - Sampler | NULL Pointer Dereference (CWE-476) — Substance3D - Sampler CWE-476 5.5 Medium 2024-10-17
CVE-2024-45127 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 4.8 Medium 2024-10-10
CVE-2024-45133 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 2.7 Low 2024-10-10
CVE-2024-45128 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 5.4 Medium 2024-10-10
CVE-2024-45124 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 5.3 Medium 2024-10-10
CVE-2024-45123 Adobe Commerce | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Commerce CWE-79 6.1 Medium 2024-10-10
CVE-2024-45121 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 4.3 Medium 2024-10-10
CVE-2024-45115 Adobe Commerce | Improper Authentication (CWE-287) — Adobe Commerce CWE-287 9.8 Critical 2024-10-10
CVE-2024-45117 Adobe Commerce | Improper Input Validation (CWE-20) — Adobe Commerce CWE-20 7.6 High 2024-10-10
CVE-2024-45116 Adobe Commerce | Cross-site Scripting (XSS) (CWE-79) — Adobe Commerce CWE-79 8.1 High 2024-10-10
CVE-2024-45119 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Commerce CWE-918 4.9 Medium 2024-10-10
CVE-2024-45122 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 4.3 Medium 2024-10-10
CVE-2024-45135 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 2.7 Low 2024-10-10
CVE-2024-45120 Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) — Adobe Commerce CWE-367 3.1 Low 2024-10-10
CVE-2024-45130 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 4.3 Medium 2024-10-10
CVE-2024-45132 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 6.5 Medium 2024-10-10
CVE-2024-45131 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 5.4 Medium 2024-10-10
CVE-2024-45148 Adobe Commerce | Improper Authentication (CWE-287) — Adobe Commerce CWE-287 8.8 High 2024-10-10
CVE-2024-45134 Adobe Commerce | Information Exposure (CWE-200) — Adobe Commerce CWE-200 2.7 Low 2024-10-10
CVE-2024-45129 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 4.3 Medium 2024-10-10
CVE-2024-45118 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 6.5 Medium 2024-10-10
CVE-2024-45149 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 2.7 Low 2024-10-10
CVE-2024-45125 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2024-10-10

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.