Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4915

Browse all 4915 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2023-29292 Server Side Request Forgery (SSRF) in FedEx carrier integration configuration — Magento Commerce CWE-918 4.9 Medium 2023-06-15
CVE-2023-29291 Server Side Request Forgery (SSRF) in USPS carrier integration configuration — Magento Commerce CWE-918 4.9 Medium 2023-06-15
CVE-2023-29290 Adobe Commerce Guest Cart Shipping Address Overwrite IDOR — Magento Commerce CWE-353 5.3 Medium 2023-06-15
CVE-2023-29289 Adobe Commerce XML Injection Security feature bypass — Magento Commerce CWE-91 6.5 Medium 2023-06-15
CVE-2023-29288 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2023-06-15
CVE-2023-29287 Adobe Commerce Information Exposure Security feature bypass — Magento Commerce CWE-200 5.3 Medium 2023-06-15
CVE-2023-22248 Adobe Commerce Incorrect Authorization Security feature bypass — Magento Commerce CWE-863 7.5 High 2023-06-15
CVE-2023-21618 ZDI-CAN-20963: Adobe Substance 3D Designer SBS File Parsing Uninitialized Variable Remote Code Execution Vulnerability — Substance3D - Designer CWE-824 7.8 High 2023-06-15
CVE-2023-29286 ZDI-CAN-20369: Adobe Substance 3D Painter USD File Parsing Uninitialized Variable Information Disclosure Vulnerability — Substance3D - Painter CWE-824 5.5 Medium 2023-05-11
CVE-2023-29285 ZDI-CAN-20360: Adobe Substance 3D Painter USD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Substance3D - Painter CWE-787 7.8 High 2023-05-11
CVE-2023-29284 ZDI-CAN-20365: Adobe Substance 3D Painter USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — Substance3D - Painter CWE-121 7.8 High 2023-05-11
CVE-2023-29283 ZDI-CAN-20361: Adobe Substance 3D Painter USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — Substance3D - Painter CWE-122 7.8 High 2023-05-11
CVE-2023-29282 ZDI-CAN-20359: Adobe Substance 3D Painter USD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Substance3D - Painter CWE-787 7.8 High 2023-05-11
CVE-2023-29281 ZDI-CAN-20364: Adobe Substance 3D Painter USD File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Substance3D - Painter CWE-125 7.8 High 2023-05-11
CVE-2023-29280 ZDI-CAN-20372: Adobe Substance 3D Painter PLY File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Substance3D - Painter CWE-125 7.8 High 2023-05-11
CVE-2023-29279 ZDI-CAN-20368: Adobe Substance 3D Painter USD File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Substance3D - Painter CWE-125 5.5 Medium 2023-05-11
CVE-2023-29278 ZDI-CAN-20371: Adobe Substance 3D Painter GLTF File Parsing Uninitialized Variable Information Disclosure Vulnerability — Substance3D - Painter CWE-824 7.8 High 2023-05-11
CVE-2023-29277 ZDI-CAN-20370: Adobe Substance 3D Painter USD File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability — Substance3D - Painter CWE-125 5.5 Medium 2023-05-11
CVE-2023-29276 ZDI-CAN-20362: Adobe Substance 3D Painter USD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Substance3D - Painter CWE-787 7.8 High 2023-05-11
CVE-2023-29275 ZDI-CAN-20363: Adobe Substance 3D Painter USD File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Substance3D - Painter CWE-125 7.8 High 2023-05-11
CVE-2023-29274 ZDI-CAN-20366: Adobe Substance 3D Painter USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Substance3D - Painter CWE-125 7.8 High 2023-05-11
CVE-2023-29273 ZDI-CAN-20367: Adobe Substance 3D Painter USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Substance3D - Painter CWE-125 7.8 High 2023-05-11
CVE-2023-26398 ZDI-CAN-20310: Adobe Substance 3D Designer USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Substance3D - Designer CWE-125 7.8 High 2023-04-13
CVE-2023-26409 ZDI-CAN-20313: Adobe Substance 3D Designer USD File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Substance3D - Designer CWE-125 7.8 High 2023-04-13
CVE-2023-26410 ZDI-CAN-20309: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution Vulnerability — Substance3D - Designer CWE-416 7.8 High 2023-04-13
CVE-2023-26411 ZDI-CAN-20312: Adobe Substance 3D Designer USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — Substance3D - Designer CWE-125 7.8 High 2023-04-13
CVE-2023-26412 ZDI-CAN-20314: Adobe Substance 3D Designer USDA File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — Substance3D - Designer CWE-121 7.8 High 2023-04-13
CVE-2023-26413 ZDI-CAN-20315: Adobe Substance 3D Designer USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — Substance3D - Designer CWE-122 7.8 High 2023-04-13
CVE-2023-26414 ZDI-CAN-20316: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution Vulnerability — Substance3D - Designer CWE-416 7.8 High 2023-04-13
CVE-2023-26415 ZDI-CAN-20317: Adobe Substance 3D Designer DAE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — Substance3D - Designer CWE-787 7.8 High 2023-04-13

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.