Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2024-41836 InDesign Desktop | NULL Pointer Dereference (CWE-476) — InDesign Desktop CWE-476 5.5 Medium 2024-07-23
CVE-2024-41839 Adobe Experience Manager | Improper Input Validation (CWE-20) — Adobe Experience Manager CWE-20 3.5 Low 2024-07-23
CVE-2024-34128 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2024-07-23
CVE-2024-34140 Adobe Bridge PDF File Parsing Memory Corruption — Bridge CWE-125 5.5 Medium 2024-07-09
CVE-2024-34139 Adobe Bridge has an integer overflow vulnerability when parsing SVG file — Bridge CWE-190 7.8 High 2024-07-09
CVE-2024-20781 Adobe Indesign TIF File Parsing Heap Memory Corruption — InDesign Desktop CWE-122 7.8 High 2024-07-09
CVE-2024-20785 Adobe Indesign 2024 TIFF File Parsing Memory Corruption Remote Code Execution vulnerability — InDesign Desktop CWE-122 7.8 High 2024-07-09
CVE-2024-20782 Adobe Indesign WMF File Parsing Out Of Bound Write — InDesign Desktop CWE-787 7.8 High 2024-07-09
CVE-2024-20783 Adobe Indesign 2024 RLE File Parsing Heap Memory Corruption — InDesign Desktop CWE-122 7.8 High 2024-07-09
CVE-2024-34123 Adobe Premiere Pro arbitrary DLL loading lead to remote code execution — Premiere Pro CWE-426 7.0 High 2024-07-09
CVE-2024-34122 T5 Acrobat Vulnerability - Exploitable crash in DecodeTile — Acrobat for Edge CWE-125 7.8 High 2024-07-02
CVE-2024-34142 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2024-06-25
CVE-2024-34141 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2024-06-25
CVE-2024-34130 Acrobat Android : OverSecured Finding : Access to arbitrary* content providers via insecure Intent configuration — Acrobat Mobile Sign Android CWE-863 5.5 Medium 2024-06-13
CVE-2024-34129 Acrobat Android : OverSecured Finding : Overwriting arbitrary files via attacker-controlled output file paths — Acrobat Mobile Sign Android CWE-22 7.5 High 2024-06-13
CVE-2024-34112 ColdFusion CFDOCUMENT file retrieval / access control bypass — ColdFusion CWE-284 7.5 High 2024-06-13
CVE-2024-34113 ColdFusion | Weak Cryptography for Passwords (CWE-261) — ColdFusion CWE-261 5.5 Medium 2024-06-13
CVE-2024-34116 Adobe Creative Cloud App Install Arbitrary Folder Delete Vulnerability can be abuse to Privilege Escalation — Creative Cloud Desktop CWE-427 7.1 High 2024-06-13
CVE-2024-34115 ZDI-CAN-24054: Adobe Substance 3D Stager SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Substance3D - Stager CWE-787 7.8 High 2024-06-13
CVE-2024-30300 Tenable Vulnerability Disclosure | Sensitive Information Disclosure Via Fake FMPS Worker — Adobe Framemaker Publishing Server CWE-200 9.8 Critical 2024-06-13
CVE-2024-30299 Tenable Vulnerability Disclosure | API Auth Bypass — Adobe Framemaker Publishing Server CWE-287 10.0 Critical 2024-06-13
CVE-2024-20753 Adobe Photoshop PDF File Parsing Memory Corruption Remote Code Execution Vulnerability — Photoshop Desktop CWE-125 7.8 High 2024-06-13
CVE-2024-30278 Adobe Media Encoder 2024 TGA File parsing memory corruption — Media Encoder CWE-125 5.5 Medium 2024-06-13
CVE-2024-34106 Insecure Direct Object Reference - An attacker can able to erase the victim quote details — Adobe Commerce CWE-863 5.3 Medium 2024-06-13
CVE-2024-34109 Adobe Commerce | Improper Input Validation (CWE-20) — Adobe Commerce CWE-20 7.2 High 2024-06-13
CVE-2024-34103 Customer account takeover via web API call & subsequent password reset — Adobe Commerce CWE-287 8.1 High 2024-06-13
CVE-2024-34110 RCE in the Adobe Commerce Webhook module through a legit webhook definition — Adobe Commerce CWE-434 7.2 High 2024-06-13
CVE-2024-34111 SSRF in service connector — Adobe Commerce CWE-918 6.5 Medium 2024-06-13
CVE-2024-34105 Stored Cross Site Scripting in Order Comment — Adobe Commerce CWE-79 4.8 Medium 2024-06-13
CVE-2024-34107 Adobe Commerce | Improper Access Control (CWE-284) — Adobe Commerce CWE-284 5.3 Medium 2024-06-13

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.