Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4915

Browse all 4915 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2021-40790 Adobe Premiere Pro MOV File Parsing Use-After-Free Information Disclosure Vulnerability — Premiere Pro CWE-416 5.5 Medium 2023-09-07
CVE-2021-40699 ColdFusion CFIDE Improper Access Control Leads To Privilege Escalation — ColdFusion CWE-284 7.4 High 2023-09-07
CVE-2021-42734 Adobe Photoshop TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Photoshop Desktop CWE-125 5.5 Medium 2023-09-07
CVE-2021-40791 Adobe Premiere Pro JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Premiere Pro CWE-125 5.5 Medium 2023-09-07
CVE-2021-42265 Adobe Premiere Pro MP4 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Premiere Pro CWE-125 5.5 Medium 2023-09-07
CVE-2021-44188 Adobe After Effects 3GP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — After Effects CWE-125 7.8 High 2023-09-07
CVE-2021-40795 Adobe Premiere Pro 3GP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Premiere Pro CWE-125 7.8 High 2023-09-07
CVE-2021-43018 Adobe Photoshop JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Photoshop Desktop CWE-787 7.8 High 2023-09-07
CVE-2021-40698 ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypass   — ColdFusion CWE-242 7.4 High 2023-09-07
CVE-2021-40723 Acrobat Reader DC Out-Of-Bounds Read Information Disclosure Vulnerability — Acrobat Reader CWE-125 5.5 Medium 2023-09-07
CVE-2021-43753 Adobe Lightroom TIF File Parsing Use-After-Free Information Disclosure Vulnerability — Lightroom Desktop CWE-416 7.8 High 2023-09-07
CVE-2021-43027 Adobe After Effects TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — After Effects CWE-125 7.8 High 2023-09-07
CVE-2021-43751 Adobe Premiere Pro MP4 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Premiere Pro CWE-125 3.3 Low 2023-09-07
CVE-2021-21088 Adobe Acrobat Pro DC Use-After-Free Remote Code Execution Vulnerability — Acrobat Reader CWE-416 7.8 High 2023-09-06
CVE-2021-36036 Magento Commerce Media Gallery Upload Improper Access Control Could Lead To Remote Code Execution — Adobe Commerce CWE-284 7.2 High 2023-09-06
CVE-2021-36021 Magento Commerce CMS Page Improper Input Validation Could Lead To Remote Code Execution — Adobe Commerce CWE-20 7.2 High 2023-09-06
CVE-2021-39859 Use After Free Adobe Acrobat Pro DC [HB-21-0339] — Acrobat Reader CWE-416 5.5 Medium 2023-09-06
CVE-2021-36023 Magento Commerce Widgets Update Layout XML Injection Vulnerability Could Lead To Remote Code Execution — Adobe Commerce CWE-78 9.1 Critical 2023-09-06
CVE-2021-36060 Adobe Media Encoder MPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Media Encoder CWE-125 5.5 Medium 2023-09-06
CVE-2021-35980 Adobe Acrobat Reader SpellDictionaryExport Path Traversal Remote Code Execution Vulnerability — Acrobat Reader CWE-22 7.8 High 2023-09-06
CVE-2021-28644 Adobe Acrobat SpellDictionaryCreate Path Traversal Remote Code Execution Vulnerability — Acrobat Reader CWE-22 7.8 High 2023-09-06
CVE-2023-38210 Other | Uncontrolled Resource Consumption (CWE-400) — XMP Toolkit CWE-400 5.5 Medium 2023-08-10
CVE-2023-38246 Adobe Acrobat Reader DC ActiveX Control (AxAcroPDFLib.AxAcroPDF) stack-based stale pointer vulnerability — Acrobat Reader CWE-824 7.8 High 2023-08-10
CVE-2023-29320 ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flaw — Acrobat Reader CWE-657 7.8 High 2023-08-10
CVE-2023-29299 Adobe Acrobat Reader Untrusted Search Path Application denial-of-service — Acrobat Reader CWE-426 4.7 Medium 2023-08-10
CVE-2023-38226 ZDI-CAN-21240: Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution Vulnerability — Acrobat Reader CWE-824 7.8 High 2023-08-10
CVE-2023-38231 ZDI-CAN-21334: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Acrobat Reader CWE-787 7.8 High 2023-08-10
CVE-2023-38228 ZDI-CAN-21317: Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability — Acrobat Reader CWE-416 7.8 High 2023-08-10
CVE-2023-29303 ZDI-CAN-20970: Adobe Acrobat Reader DC AcroForm Annotation Use-After-Free Information Disclosure Vulnerability — Acrobat Reader CWE-416 5.5 Medium 2023-08-10
CVE-2023-38225 ZDI-CAN-21118: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability — Acrobat Reader CWE-416 7.8 High 2023-08-10

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.