Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4915

Browse all 4915 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2023-44361 ZDI-CAN-22041: Adobe Acrobat Reader DC AcroForm Doc Object Use-After-Free Information Disclosure Vulnerability — Acrobat Reader CWE-416 5.5 Medium 2023-11-16
CVE-2023-44371 ZDI-CAN-21998: Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability — Acrobat Reader CWE-416 7.8 High 2023-11-16
CVE-2023-44358 ZDI-CAN-21971: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Acrobat Reader CWE-125 5.5 Medium 2023-11-16
CVE-2023-44339 ZDI-CAN-21422: Adobe Acrobat Reader DC AcroForm value Out-Of-Bounds Read Information Disclosure Vulnerability — Acrobat Reader CWE-125 5.5 Medium 2023-11-16
CVE-2023-44336 TALOS-2023-1794 - Adobe Acrobat Reader Thermometer use-after-free vulnerability — Acrobat Reader CWE-416 7.8 High 2023-11-16
CVE-2023-44365 ZDI-CAN-21931: Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution Vulnerability — Acrobat Reader CWE-824 7.8 High 2023-11-16
CVE-2023-44367 ZDI-CAN-21929: Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability — Acrobat Reader CWE-416 7.8 High 2023-11-16
CVE-2023-44337 ZDI-CAN-21509: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Acrobat Reader CWE-125 7.8 High 2023-11-16
CVE-2023-44372 TALOS-2023-1842 - Adobe Acrobat Reader U3D page event use-after-free vulnerability — Acrobat Reader CWE-416 7.8 High 2023-11-16
CVE-2023-44323 PDF Jbig2 memory-corruption Vulnerability - MSFT T5 — Acrobat for Edge CWE-416 5.5 Medium 2023-10-30
CVE-2023-38251 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) — Adobe Commerce CWE-400 5.3 Medium 2023-10-13
CVE-2023-38219 Validate Your Inputs | Cross-site Scripting (Stored XSS) (CWE-79) - Customer to Admin stored XSS with Gift wrapping — Adobe Commerce CWE-79 8.7 High 2023-10-13
CVE-2023-38220 Full page cache enumeration via cookie X-Magento-Vary — Adobe Commerce CWE-285 7.5 High 2023-10-13
CVE-2023-26367 Error based file extraction via PHP filter chains during product bulk import logic — Adobe Commerce CWE-20 4.9 Medium 2023-10-13
CVE-2023-26366 Validate Your Inputs | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Commerce CWE-918 6.8 Medium 2023-10-13
CVE-2023-38218 Incorrect Authorization - Customer account takeover — Adobe Commerce CWE-863 8.8 High 2023-10-13
CVE-2023-38250 Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) — Adobe Commerce CWE-89 8.0 High 2023-10-13
CVE-2023-38249 Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) — Adobe Commerce CWE-89 8.0 High 2023-10-13
CVE-2023-38221 Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) — Adobe Commerce CWE-89 8.0 High 2023-10-13
CVE-2023-26370 ZDI-CAN-21257: Adobe Photoshop PSD File Parsing Uninitialized Variable Remote Code Execution Vulnerability — Photoshop Desktop CWE-824 7.8 High 2023-10-11
CVE-2023-38217 ZDI-CAN-21403: Adobe Bridge Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Bridge CWE-125 5.5 Medium 2023-10-11
CVE-2023-38216 ZDI-CAN-21404: Adobe Bridge Font Parsing Use-After-Free Information Disclosure Vulnerability — Bridge CWE-416 5.5 Medium 2023-10-11
CVE-2023-38204 Bypass APSB23-41 (CVE-2023-38203) - Pre-Auth RCE ColdFusion 2021 Update 8 — ColdFusion CWE-502 9.8 Critical 2023-09-14
CVE-2023-38205 ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 — ColdFusion CWE-284 7.5 High 2023-09-14
CVE-2023-38206 ColdFusion | Improper Access Control (CWE-284) — ColdFusion CWE-284 5.3 Medium 2023-09-14
CVE-2023-38215 Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2023-09-13
CVE-2023-38214 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2023-09-13
CVE-2023-29305 Adobe Connect Reflected Cross-Site Scripting (XSS) Arbitrary code execution — Adobe Connect CWE-79 6.1 Medium 2023-09-13
CVE-2023-29306 Adobe Connect Reflected Cross-Site Scripting (XSS) Arbitrary code execution — Adobe Connect CWE-79 6.1 Medium 2023-09-13
CVE-2023-26369 [Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild — Acrobat Reader CWE-787 7.8 High 2023-09-13

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.