Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2024-39418 Adobe Commerce | Improper Authorization (CWE-285) — Adobe Commerce CWE-285 5.4 Medium 2024-08-14
CVE-2024-39413 An unauthorized user can export the Invoiced Sales Report — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-39408 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) — Adobe Commerce CWE-352 4.3 Medium 2024-08-14
CVE-2024-39399 [Paris] Path Traversal lead to local file read — Adobe Commerce CWE-22 7.7 High 2024-08-14
CVE-2024-39417 An unauthorized user can export the Shipping Report — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-39410 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) — Adobe Commerce CWE-352 4.3 Medium 2024-08-14
CVE-2024-39398 OTP 2FA can be bruteforced — Adobe Commerce CWE-307 7.4 High 2024-08-14
CVE-2024-39407 Adobe Commerce | Improper Authorization (CWE-285) — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-39401 Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — Adobe Commerce CWE-78 8.4 High 2024-08-14
CVE-2024-39397 Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) — Adobe Commerce CWE-434 9.0 Critical 2024-08-14
CVE-2024-39411 Adobe Commerce | Improper Authorization (CWE-285) — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-39409 Adobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352) — Adobe Commerce CWE-352 4.3 Medium 2024-08-14
CVE-2024-39416 Unauthorized user can export Orders Sale Report — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-39414 Being able to import/export tax rates without proper privileges — Adobe Commerce CWE-284 4.3 Medium 2024-08-14
CVE-2024-39412 Adobe Commerce | Improper Authorization (CWE-285) — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-39406 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce CWE-22 6.8 Medium 2024-08-14
CVE-2024-39402 Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — Adobe Commerce CWE-78 8.4 High 2024-08-14
CVE-2024-39400 DOM XSS through integrations can impact other admins — Adobe Commerce CWE-79 8.1 High 2024-08-14
CVE-2024-39404 A user without Shop Policy Parameters section privilege can alter the shop policy parameters section — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-39405 Adobe Commerce | Improper Authorization (CWE-285) — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-39415 An unauthorized user can export the Tax Sales Report — Adobe Commerce CWE-285 4.3 Medium 2024-08-14
CVE-2024-41864 Adobe Substance 3D Designer ICO Parsing Out-Of-Bounds Write Vulnerability — Substance3D - Designer CWE-787 7.8 High 2024-08-14
CVE-2024-41862 Adobe Substance 3D Sampler Memory Corruption Out-of-Bounds-READ Vulnerability II, when parsing PSD file — Substance3D - Sampler CWE-125 5.5 Medium 2024-08-14
CVE-2024-41861 Adobe Substance 3D Sampler Memory Corruption Out-of-Bounds-READ Vulnerability I, when parsing PSD file — Substance3D - Sampler CWE-125 5.5 Medium 2024-08-14
CVE-2024-41860 Adobe Substance 3D Sampler Memory Corruption Vulnerability I, when parsing PSD file — Substance3D - Sampler CWE-125 5.5 Medium 2024-08-14
CVE-2024-41863 Adobe Substance 3D Sampler Memory Corruption Out-of-Bounds-READ Vulnerability III, when parsing DNG file — Substance3D - Sampler CWE-125 5.5 Medium 2024-08-14
CVE-2024-41858 Adobe InCopy has an integer overflow vulnerability when parsing SVG file — InCopy CWE-190 7.8 High 2024-08-14
CVE-2024-39392 Adobe Indesign 2024 EPS File Parsing Heap Memory Corruption Remote Code Execution Vulnerability — InDesign Desktop CWE-122 7.8 High 2024-08-02
CVE-2024-39396 Adobe Indesign 2024 PCX File Parsing Out Of Bound Read — InDesign Desktop CWE-125 5.5 Medium 2024-08-02
CVE-2024-39379 Acrobat for Edge | Out-of-bounds Read (CWE-125) — Acrobat for Edge CWE-125 5.5 Medium 2024-07-31

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.