CVE-2011-0627High· 8.8▾ Midnight⚠ Exploited in the wildAdobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 1 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.1%
5.1% → 5.1%
Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
flash_player <= 10.2.159.1flash_player = 6.0.21.0flash_player = 6.0.79flash_player = 7.0flash_player = 7.0.1flash_player = 7.0.14.0flash_player = 7.0.19.0flash_player = 7.0.24.0flash_player = 7.0.25flash_player = 7.0.53.0flash_player = 7.0.60.0flash_player = 7.0.61.0flash_player = 7.0.63flash_player = 7.0.66.0flash_player = 7.0.67.0flash_player = 7.0.68.0flash_player = 7.0.69.0flash_player = 7.0.70.0flash_player = 7.0.73.0flash_player = 7.1flash_player = 7.1.1flash_player = 7.2flash_player = 8.0flash_player = 8.0.22.0flash_player = 8.0.24.0flash_player = 8.0.33.0flash_player = 8.0.34.0flash_player = 8.0.35.0flash_player = 8.0.39.0flash_player = 8.0.42.0flash_player = 9.0flash_player = 9.0.16flash_player = 9.0.18d60flash_player = 9.0.20flash_player = 9.0.20.0flash_player = 9.0.28flash_player = 9.0.28.0flash_player = 9.0.31flash_player = 9.0.31.0flash_player = 9.0.45.0flash_player = 9.0.47.0flash_player = 9.0.48.0flash_player = 9.0.112.0flash_player = 9.0.114.0flash_player = 9.0.115.0flash_player = 9.0.124.0flash_player = 9.0.125.0flash_player = 9.0.151.0flash_player = 9.0.152.0flash_player = 9.0.155.0flash_player = 9.0.159.0flash_player = 9.0.246.0flash_player = 9.0.260.0flash_player = 9.0.262.0flash_player = 9.0.277.0flash_player = 9.0.283.0flash_player = 9.125.0flash_player = 10.0.0.584flash_player = 10.0.12.10flash_player = 10.0.12.36flash_player = 10.0.15.3flash_player = 10.0.22.87flash_player = 10.0.32.18flash_player = 10.0.42.34flash_player = 10.0.45.2flash_player = 10.1.52.14.1flash_player = 10.1.52.15flash_player = 10.1.53.64flash_player = 10.1.82.76flash_player = 10.1.85.3flash_player = 10.1.92.8flash_player = 10.1.92.10flash_player = 10.1.95.1flash_player = 10.1.95.2flash_player = 10.1.102.64flash_player = 10.2.152flash_player = 10.2.152.32flash_player = 10.2.152.33flash_player = 10.2.154.13flash_player = 10.2.154.25flash_player <= 10.2.157.51flash_player = 10.1.105.6flash_player = 10.1.106.16flash_player = 10.2.156.12Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2016-4117Critical· 9.8Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
CVE-2018-15982High· 7.8Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability
CVE-2026-75999High· 8.4ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-75991High· 8.6Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-75726Low· 3.5Adobe Experience Manager is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass
CVE-2018-15454High· 8.6A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an …