Adobe vendor intelligence
Adobe Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Adobe products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 98
- Known exploited vulnerabilities affecting Adobe products
- In CISA KEV
- 80
- Records also listed in the official catalog
- Beyond CISA KEV
- 18
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 3
- Adobe KEVs with sensor-observed exploitation activity
The catalog gap matters for Adobe exposure
Eighteen of the 98 exploited Adobe CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 18% of this vendor portfolio.
- 82%
- Covered by CISA
- 18%
- Beyond CISA
- 23
- Product families
Attested Adobe CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-48313
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
ColdFusion | Confirmed | Beyond CISA | 04 Aug 2026 |
|
CVE-2026-48282
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
ColdFusion | Confirmed | In CISA | 02 Jul 2026 |
|
CVE-2025-49533
Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502) |
Adobe Experience Manager (MS) | High | Beyond CISA | 21 Oct 2025 |
|
CVE-2021-21087
ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser |
ColdFusion | High | Beyond CISA | 26 Jul 2025 |
|
CVE-2026-34621
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) |
Acrobat Reader | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-9715
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an... |
Adobe Acrobat and Reader | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-54236
Adobe Commerce | Improper Input Validation (CWE-20) |
Adobe Commerce | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-54253
Adobe Experience Manager | Incorrect Authorization (CWE-863) |
Adobe Experience Manager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-54254
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) |
Adobe Experience Manager | High | Beyond CISA | 05 Aug 2025 |
|
CVE-2014-0515
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356... |
Flash Player | High | Beyond CISA | 29 Apr 2014 |
|
CVE-2013-5331
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe... |
Flash Player | High | Beyond CISA | 11 Dec 2013 |
|
CVE-2013-0634
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on... |
Flash Player | High | Beyond CISA | 08 Feb 2013 |
|
CVE-2013-0633
Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before... |
Flash Player | High | Beyond CISA | 08 Feb 2013 |
|
CVE-2012-0779
Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and... |
Flash Player | High | Beyond CISA | 04 May 2012 |
|
CVE-2011-4369
Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6... |
Reader and Acrobat | High | Beyond CISA | 16 Dec 2011 |
|
CVE-2011-2444
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7... |
Flash Player | High | Beyond CISA | 22 Sep 2011 |
|
CVE-2011-2110
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to... |
Flash Player | High | Beyond CISA | 16 Jun 2011 |
|
CVE-2011-0627
Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute... |
Flash Player | High | Beyond CISA | 13 May 2011 |
|
CVE-2010-3654
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll... |
Flash Player | High | Beyond CISA | 29 Oct 2010 |
|
CVE-2010-3653
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of... |
Shockwave Player | High | Beyond CISA | 26 Oct 2010 |
|
CVE-2010-2884
Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and... |
Flash Player, Reader, Acrobat | High | Beyond CISA | 15 Sep 2010 |
|
CVE-2009-3459
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute... |
Reader and Acrobat | Confirmed | In CISA | 13 Oct 2009 |
|
CVE-2009-0658
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF... |
Reader | High | Beyond CISA | 20 Feb 2009 |
|
CVE-2008-3873
The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a... |
Flash Player | High | Beyond CISA | 29 Aug 2008 |
|
CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the... |
Adobe Flash Player before 28.0.0.161 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-15961
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload... |
ColdFusion | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-4939
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data... |
Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-28550
Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution |
Acrobat Reader | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-21017
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution |
Acrobat Reader | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to... |
Flash Player | Confirmed | In CISA | 15 Feb 2022 |
|
CVE-2022-24086
Adobe Commerce checkout improper input validation leads to remote code execution |
Magento Commerce | Confirmed | In CISA | 15 Feb 2022 |
|
CVE-2008-2992
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that... |
Acrobat and Reader | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2010-0188
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2011-0611
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140;... |
Flash Player, AIR, Reader, Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2012-1535
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-0632
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary... |
ColdFusion | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-0640
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-0641
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-3346
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2014-0496
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to... |
Reader and Acrobat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-3043
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-7645
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-1019
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-4117
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-7855
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers... |
Flash Player | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-11292
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in... |
Adobe Flash Player version 27.0.0.159 and earlier | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2009-3960
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0,... |
BlazeDS | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-0625
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-0629
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-0631
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in... |
ColdFusion | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2009-0927
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute... |
Reader and Acrobat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2010-2861
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read... |
ColdFusion | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-4171
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as... |
Flash Player | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-7892
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField... |
Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2012-2034
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on... |
Flash Player | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2013-2729
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary... |
Reader and Acrobat | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2014-9163
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-0311
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-0313
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-3113
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-5122
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-5123
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2018-5002
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to... |
Adobe Flash Player 29.0.0.171 and earlier versions | Confirmed | In CISA | 23 May 2022 |
|
CVE-2014-0546
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and... |
Reader and Acrobat | Confirmed | In CISA | 25 May 2022 |
|
CVE-2014-8439
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-8651
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux,... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-0310
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-0984
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-1010
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2007-5659
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2008-0655
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-1862
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87,... |
["Reader", "Acrobat", "Flash Player"] | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-3953
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-4324
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2010-1297
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and... |
Flash Player, AIR, Reader, Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2010-2883
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2011-0609
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2011-2462
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-0754
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-0767
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2012-5054
Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute... |
Flash Player | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2018-4990
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free... |
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 15 Mar 2023 |
|
CVE-2023-38205
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 |
ColdFusion | Confirmed | In CISA | 20 Jul 2023 |
|
CVE-2023-29298
Adobe ColdFusion Improper Access Control Security feature bypass |
ColdFusion | Confirmed | In CISA | 20 Jul 2023 |
|
CVE-2023-26359
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 21 Aug 2023 |
|
CVE-2023-26369
[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild |
Acrobat Reader | Confirmed | In CISA | 14 Sep 2023 |
|
CVE-2023-21608
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability |
Acrobat Reader | Confirmed | In CISA | 10 Oct 2023 |
|
CVE-2023-38203
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE |
ColdFusion | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2023-29300
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution |
ColdFusion | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access |
Adobe Commerce | Confirmed | In CISA | 17 Jul 2024 |
|
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2013-0643
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2013-0648
Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2014-0502
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before... |
Flash Player | Confirmed | In CISA | 17 Sep 2024 |
|
CVE-2024-20767
ColdFusion | Improper Access Control (CWE-284) |
ColdFusion | Confirmed | In CISA | 16 Dec 2024 |
|
CVE-2017-3066
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization... |
Adobe ColdFusion ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier | Confirmed | In CISA | 24 Feb 2025 |
No Adobe CVEs match this search or filter.
Showing 98 of 98 Adobe known exploited vulnerabilities.
Recurring weakness patterns
Use after free, out-of-bounds write, and restriction account for 35 mapped occurrences across this Adobe KEV portfolio.
CWE-416
Use After Free
CWE-787
Out-of-bounds Write
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-502
Deserialization of Untrusted Data
CWE-190
Integer Overflow or Wraparound
CWE-284
Improper Access Control
CWE-20
Improper Input Validation
CWE-121
Stack-based Buffer Overflow
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.