Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Adobe

9,132 known vulnerabilities

362
CRITICAL
959
HIGH
546
MEDIUM
15
LOW

Top Products

acrobat dc 966 acrobat reader dc 966 acrobat 288 acrobat reader 174 experience manager 151 reader 148 flash player 107 coldfusion 86 flash player desktop runtime 59 c2pa 49
1,882 CVEs · Page 3/38
7.8
CVE-2026-48370

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-48369

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co

7.8
CVE-2026-48367

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-48366

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-48344

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could resul

7.8
CVE-2026-48343

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

7.8
CVE-2026-48342

Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in t

7.8
CVE-2026-48341

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

7.8
CVE-2026-48340

Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in th

7.8
CVE-2026-48339

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the co

6.8
CVE-2026-48338

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit

7.7
CVE-2026-48332

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature byp

2.7
CVE-2026-48329

ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypas

7.7
CVE-2026-48328

ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A l

9.0
CVE-2026-48327

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the

9.3
CVE-2026-48325

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary co

9.1
CVE-2026-48324

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulner

9.9
CVE-2026-48322

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result i

9.3
CVE-2026-48321

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacke

8.5
CVE-2026-48320

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerabi

9.1
CVE-2026-48319

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit

9.9
CVE-2026-48318

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit

7.8
CVE-2026-48311

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

5.9
CVE-2026-48308

Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A

9.6
CVE-2026-48284

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in th

7.8
CVE-2026-48274

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-48272

Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary c

7.8
CVE-2026-48270

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co

7.8
CVE-2026-48269

Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in

5.5
CVE-2026-47979

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An a

7.8
CVE-2026-47976

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-47971

Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i

5.4
CVE-2026-48371

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged

9.6
CVE-2026-48359

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t

9.1
CVE-2026-48358

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co

9.3
CVE-2026-48356

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi

5.4
CVE-2026-48355

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-

8.6
CVE-2026-48350

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability t

8.1
CVE-2026-48349

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con

7.7
CVE-2026-48348

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con

7.7
CVE-2026-48347

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul

7.9
CVE-2026-48346

Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte

8.2
CVE-2026-48345

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul

8.6
CVE-2026-48310

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'

5.4
CVE-2026-48263

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-

5.4
CVE-2026-48262

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit

5.4
CVE-2026-48261

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit

5.4
CVE-2026-48260

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit

9.6
CVE-2026-48259

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrar

5.4
CVE-2026-48257

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit

Frequently Asked Questions

How many CVEs affect Adobe?

Adobe has 9,132 CVE records in our database, including 1506 critical and 3028 high severity vulnerabilities. 10 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Adobe vulnerabilities?

Adobe has 1506 critical severity (CVSS 9.0+) and 3028 high severity (CVSS 7.0-8.9) vulnerabilities. 10 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Adobe vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Adobe products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Adobe Vulnerabilities

CyberStrike scans your infrastructure for Adobe vulnerabilities and provides real-time remediation guidance.

Get Started