Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Adobe

14,318 known vulnerabilities

480
CRITICAL
2,433
HIGH
2,281
MEDIUM
135
LOW

Top Products

acrobat dc 1468 acrobat reader dc 1468 experience manager 1148 acrobat 682 acrobat reader 569 indesign 200 commerce 198 experience manager cloud service 183 coldfusion 182 magento 175
5,329 CVEs · Page 25/107
6.5
CVE-2025-27207

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access

5.3
CVE-2025-27206

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access

7.8
CVE-2025-43572

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary

7.8
CVE-2025-43571

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi

7.8
CVE-2025-43570

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi

7.8
CVE-2025-43569

Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2025-43568

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi

9.3
CVE-2025-43567

Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could

6.8
CVE-2025-43566

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restr

8.4
CVE-2025-43565

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c

9.1
CVE-2025-43564

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c

9.1
CVE-2025-43563

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c

9.1
CVE-2025-43562

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements

9.1
CVE-2025-43561

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c

9.1
CVE-2025-43560

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that

9.1
CVE-2025-43559

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that

7.8
CVE-2025-43554

Substance3D - Modeler versions 1.21.0 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2025-43553

Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that

5.5
CVE-2025-43551

Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d

7.8
CVE-2025-43549

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbi

7.8
CVE-2025-43548

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary

5.4
CVE-2025-30316

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be

6.1
CVE-2025-30315

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be

6.1
CVE-2025-30314

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be

7.8
CVE-2025-43557

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could

7.8
CVE-2025-43556

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could

7.8
CVE-2025-43555

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha

7.8
CVE-2025-43547

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could re

7.8
CVE-2025-43546

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that

7.8
CVE-2025-43545

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could r

7.8
CVE-2025-30330

Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu

5.5
CVE-2025-30329

Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to

7.8
CVE-2025-30328

Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in a

7.8
CVE-2025-30326

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Access of Uninitialized Pointer vulnerability th

7.8
CVE-2025-30325

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability tha

7.8
CVE-2025-30324

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi

7.8
CVE-2025-30322

Substance3D - Painter versions 11.0 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2025-27197

Lightroom Desktop versions 8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arb

5.5
CVE-2025-30320

InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou

5.5
CVE-2025-30319

InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou

7.8
CVE-2025-30318

InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by an out-of-bounds write vulnerability that could r

7.8
CVE-2025-30310

Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confu

2.7
CVE-2025-27192

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficien

5.3
CVE-2025-27191

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Ac

5.3
CVE-2025-27190

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Ac

4.3
CVE-2025-27189

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site R

4.3
CVE-2025-27188

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Au

6.8
CVE-2025-30294

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that

6.8
CVE-2025-30293

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that

6.1
CVE-2025-30292

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerab

Frequently Asked Questions

How many CVEs affect Adobe?

Adobe has 14,318 CVE records in our database, including 1684 critical and 8092 high severity vulnerabilities. 26 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Adobe vulnerabilities?

Adobe has 1684 critical severity (CVSS 9.0+) and 8092 high severity (CVSS 7.0-8.9) vulnerabilities. 26 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Adobe vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Adobe products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Adobe Vulnerabilities

CyberStrike scans your infrastructure for Adobe vulnerabilities and provides real-time remediation guidance.

Get Started