Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Adobe — Vulnerabilities & Security Advisories 4340

Browse all 4340 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE IDTitleCVSSSeverityPublished
CVE-2024-26040 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26094 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26042 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26028 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26118 Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26105 Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26032 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26052 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26107 Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26045 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26125 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-20768 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26041 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-26043 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience ManagerCWE-79 5.4 Medium2024-03-18
CVE-2024-20762 Adobe Animate MP3 File parsing unitialized heap memory corruption — AnimateCWE-125 5.5 Medium2024-03-18
CVE-2024-20764 Adobe Animate 2024 SWF File parsing memory corruption — AnimateCWE-125 5.5 Medium2024-03-18
CVE-2024-20763 Adobe Animate 2024 GIF file parsing memory corruption — AnimateCWE-125 5.5 Medium2024-03-18
CVE-2024-20761 Adobe Animate 2024 BMP File Parsing Out-Of-Bound Write Remote Code execution Vulnerability — AnimateCWE-787 7.8 High2024-03-18
CVE-2024-20754 Lightroom Desktop | Untrusted Search Path (CWE-426) — Lightroom DesktopCWE-426 7.8 High2024-03-18
CVE-2024-20757 Bridge 2024 TIF File Parsing Out-Of-Bound Read Information Disclosure Vulnerability — BridgeCWE-125 5.5 Medium2024-03-18
CVE-2024-20755 Adobe Bridge PDF Parsing Heap Memory Corruption Remote Code Execution Vulnerability — BridgeCWE-122 7.8 High2024-03-18
CVE-2024-20752 ZDI-CAN-22653: Adobe Bridge PS File Parsing Use-After-Free Remote Code Execution Vulnerability — BridgeCWE-416 7.8 High2024-03-18
CVE-2024-20756 Adobe Bridge 2024 Out of Bound Write Remote Code Execution Vulnerability — BridgeCWE-787 7.8 High2024-03-18
CVE-2024-20746 Adobe Premiere Pro Out-of-bounds Write Arbitrary code execution — Premiere ProCWE-787 7.8 High2024-03-18
CVE-2024-20745 ZDI-CAN-22671: Adobe Premiere Pro AVI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — Premiere ProCWE-122 7.8 High2024-03-18
CVE-2024-20767 ColdFusion | Improper Access Control (CWE-284) — ColdFusionCWE-284 7.4 High2024-03-18
CVE-2024-20765 ZDI-CAN-22674: Adobe Acrobat Reader DC PDF File Parsing Use-After-Free Remote Code Execution Vulnerability — Acrobat ReaderCWE-416 7.8 High2024-02-29
CVE-2024-20716 Force high-usage of resources by generating unlimited coupons: Adobe Commerce — Adobe CommerceCWE-400 4.9 Medium2024-02-15
CVE-2024-20717 Stored admin XSS via PayPal authentication certificate — Adobe CommerceCWE-79 5.4 Medium2024-02-15
CVE-2024-20719 [Adobe Commerce] Stored XSS from low privileged admin user on every admin page, bypassing CVE-2023-29297 — Adobe CommerceCWE-79 9.1 Critical2024-02-15

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.