Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4483

Browse all 4483 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE IDTitleCVSSSeverityPublished
CVE-2026-48315 ColdFusion | Improper Input Validation (CWE-20) — ColdFusionCWE-20 9.3 Critical2026-06-30
CVE-2026-48277 ColdFusion | Improper Input Validation (CWE-20) — ColdFusionCWE-20 10.0 Critical2026-06-30
CVE-2026-48281 ColdFusion | Improper Input Validation (CWE-20) — ColdFusionCWE-20 10.0 Critical2026-06-30
CVE-2026-48285 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) — ColdFusionCWE-918 8.6 High2026-06-30
CVE-2026-48313 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusionCWE-22 9.3 Critical2026-06-30
CVE-2026-48307 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) — ColdFusionCWE-79 8.8 High2026-06-30
CVE-2026-48314 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusionCWE-22 6.5 Medium2026-06-30
CVE-2026-48276 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) — ColdFusionCWE-434 10.0 Critical2026-06-30
CVE-2026-48282 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusionCWE-22 10.0 Critical2026-06-30
CVE-2026-48283 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) — ColdFusionCWE-434 10.0 Critical2026-06-30
CVE-2026-48286 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) — Adobe Campaign Classic (ACC)CWE-863 10.0 Critical2026-06-30
CVE-2020-9695 Acrobat Reader | Out-of-bounds Write (CWE-787) — Acrobat ReaderCWE-787 7.8 High2026-06-23
CVE-2020-9711 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat ReaderCWE-125 5.5 Medium2026-06-23
CVE-2020-9713 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat ReaderCWE-125 5.5 Medium2026-06-23
CVE-2026-48294 Adobe acrobat 跨站脚本漏洞 — Adobe Acrobat PDF Extension (Chrome)CWE-79 7.4 High2026-06-16
CVE-2026-47963 DNG SDK | Out-of-bounds Read (CWE-125) — DNG SDKCWE-125 5.5 Medium2026-06-16
CVE-2026-47934 DNG SDK | Out-of-bounds Read (CWE-125) — DNG SDKCWE-125 5.5 Medium2026-06-16
CVE-2026-47927 DNG SDK | Out-of-bounds Read (CWE-125) — DNG SDKCWE-125 5.5 Medium2026-06-16
CVE-2026-47964 DNG SDK | Heap-based Buffer Overflow (CWE-122) — DNG SDKCWE-122 7.8 High2026-06-16
CVE-2026-47965 Acrobat Reader | Out-of-bounds Write (CWE-787) — Acrobat ReaderCWE-787 7.8 High2026-06-12
CVE-2026-34711 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) — CAI Content CredentialsCWE-190 7.5 High2026-06-09
CVE-2026-34712 CAI Content Credentials | Improper Input Validation (CWE-20) — CAI Content CredentialsCWE-20 7.5 High2026-06-09
CVE-2026-47904 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — CAI Content CredentialsCWE-400 6.2 Medium2026-06-09
CVE-2026-47903 CAI Content Credentials | Improper Input Validation (CWE-20) — CAI Content CredentialsCWE-20 6.2 Medium2026-06-09
CVE-2026-47902 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — CAI Content CredentialsCWE-400 6.2 Medium2026-06-09
CVE-2026-47905 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — CAI Content CredentialsCWE-400 6.2 Medium2026-06-09
CVE-2026-34657 CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — CAI Content CredentialsCWE-22 5.5 Medium2026-06-09
CVE-2026-34713 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — CAI Content CredentialsCWE-400 7.5 High2026-06-09
CVE-2026-47938 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Campaign Classic (ACC)CWE-918 10.0 Critical2026-06-09
CVE-2026-48303 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) — Adobe Campaign Classic (ACC)CWE-863 10.0 Critical2026-06-09

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.