Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | ColdFusion | 0 ~ 2021.12 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit for CVE-2024-20767 - Adobe ColdFusion | https://github.com/yoryio/CVE-2024-20767 | POC Details |
| 2 | Proof of Concept for CVE-2024-20767. Arbitrary file read from Adobe ColdFusion | https://github.com/m-cetin/CVE-2024-20767 | POC Details |
| 3 | Exploit Toolkit for Adobe ColdFusion CVE-2024-20767 Vulnerability | https://github.com/Chocapikk/CVE-2024-20767 | POC Details |
| 4 | None | https://github.com/huyqa/cve-2024-20767 | POC Details |
| 5 | Exploit for CVE-2024-20767 affecting Adobe ColdFusion | https://github.com/Praison001/CVE-2024-20767-Adobe-ColdFusion | POC Details |
| 6 | ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to sensitive files and perform arbitrary file system write. Exploitation of this issue does not require user interaction. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-20767.yaml | POC Details |
| 7 | None | https://github.com/alm6no5/CVE-2024-20767 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-20745 | 7.8 HIGH | ZDI-CAN-22671: Adobe Premiere Pro AVI File Parsing Heap-based Buffer Overflow Remote Code |
| CVE-2024-20761 | 7.8 HIGH | Adobe Animate 2024 BMP File Parsing Out-Of-Bound Write Remote Code execution Vulnerability |
| CVE-2024-20754 | 7.8 HIGH | Lightroom Desktop | Untrusted Search Path (CWE-426) |
| CVE-2024-20755 | 7.8 HIGH | Adobe Bridge PDF Parsing Heap Memory Corruption Remote Code Execution Vulnerability |
| CVE-2024-20746 | 7.8 HIGH | Adobe Premiere Pro Out-of-bounds Write Arbitrary code execution |
| CVE-2024-20752 | 7.8 HIGH | ZDI-CAN-22653: Adobe Bridge PS File Parsing Use-After-Free Remote Code Execution Vulnerabi |
| CVE-2024-20756 | 7.8 HIGH | Adobe Bridge 2024 Out of Bound Write Remote Code Execution Vulnerability |
| CVE-2024-20762 | 5.5 MEDIUM | Adobe Animate MP3 File parsing unitialized heap memory corruption |
| CVE-2024-20764 | 5.5 MEDIUM | Adobe Animate 2024 SWF File parsing memory corruption |
| CVE-2024-20763 | 5.5 MEDIUM | Adobe Animate 2024 GIF file parsing memory corruption |
| CVE-2024-20757 | 5.5 MEDIUM | Bridge 2024 TIF File Parsing Out-Of-Bound Read Information Disclosure Vulnerability |
| CVE-2024-26104 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2024-26103 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2024-26051 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2024-26101 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2024-26096 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2024-26031 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2024-26059 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2024-26106 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2024-26056 | 5.4 MEDIUM | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
Showing top 20 of 56 CVEs. View all on vendor page → →
No comments yet