VulnSea

adobe has 509 CVEs on record between 2010 and 2026. Disclosure cadence is accelerating: 251 in the last 90 days against 72 in the 90 before. The busiest recent month was September 2026 with 224. The median CVSS is 6.2 (medium), with 52 rated critical. 2% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 2139 days (8 cases). The dominant weakness classes are CWE-79 (198) and CWE-787 (55). Most affected products: experience_manager (185), acrobat (37), coldfusion (32).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
6.2
Publish → KEV
2139 d median(8)
Last 90 days
251 prev 72

Products

  • experience_manager 185
  • acrobat 37
  • coldfusion 32
  • commerce 28
  • campaign 22
  • after_effects 18
509
Total CVEs
52
Critical
8
CISA KEV
9
Exploited

Adobe vulnerabilities

CVEs affecting Adobe, newest first. Open any entry for full detail, references, and exploit status.

509 CVEsRSS

CVE-2025-64537Critical· 9.3
9mo ago

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious sc…

▾ Midnightadobe · experience_managerEPSS 0.74%via NVD
CVE-2025-64897Medium· 5.6
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized writ…

▾ Sunlitadobe · coldfusionEPSS 0.13%via NVD
CVE-2025-61823Medium· 6.2
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could explo…

▾ Sunlitadobe · coldfusionEPSS 0.49%via NVD
CVE-2025-61822Medium· 6.2
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to …

▾ Sunlitadobe · coldfusionEPSS 0.65%via NVD
CVE-2025-61812High· 8.4
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require…

▾ Twilightadobe · coldfusionEPSS 4.7%via NVD
CVE-2025-61811Critical· 9.1
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage…

▾ Midnightadobe · coldfusionEPSS 1.2%via NVD
CVE-2025-61810High· 8.4
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could…

▾ Twilightadobe · coldfusionEPSS 9.5%via NVD
CVE-2025-61809Critical· 9.1
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures…

▾ Midnightadobe · coldfusionEPSS 0.66%via NVD
CVE-2025-61808Critical· 9.1
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. Exploitation of this is…

▾ Midnightadobe · coldfusionEPSS 11%via NVD
CVE-2025-61813High· 7.4
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnera…

▾ Twilightadobe · coldfusionEPSS 0.55%via NVD
CVE-2025-64898Medium· 5.3
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain …

▾ Sunlitadobe · coldfusionEPSS 0.44%via NVD
CVE-2025-61821Medium· 6.8
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnera…

▾ Sunlitadobe · coldfusionEPSS 0.53%via NVD
CVE-2025-64899High· 7.8
9mo ago

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an all…

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an all…

▾ Twilightadobe · acrobatEPSS 0.50%via NVD
CVE-2025-64896Medium· 5.5
9mo ago

Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could lead to application denial-of-service

Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could lead to application denial-of-service. An attacker could exploit this vul…

▾ Sunlitadobe · creative_cloudEPSS 0.18%via NVD
CVE-2025-64787Low· 3.3
9mo ago

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An…

▾ Sunlitadobe · acrobatEPSS 0.45%via NVD
CVE-2025-64786Low· 3.3
9mo ago

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An…

▾ Sunlitadobe · acrobatEPSS 0.43%via NVD
CVE-2025-64785High· 7.8
9mo ago

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the cu…

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the cu…

▾ Twilightadobe · acrobatEPSS 0.48%via NVD
CVE-2022-42343Medium· 6.5
3y ago

Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read

Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the app…

▾ Sunlitadobe · campaignEPSS 1.4%via NVD
CVE-2021-21009High· 8.6
5y ago

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Su…

▾ Twilightadobe · campaignEPSS 3.0%via NVD
CVE-2020-9666Medium· 5.5
6y ago

Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability

Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

▾ Sunlitadobe · campaignEPSS 2.3%via NVD
CVE-2019-7106Critical· 9.8
7y ago

Adobe XD versions 16.0 and earlier have a path traversal vulnerability

Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

▾ Midnightadobe · xdEPSS 6.2%via NVD
CVE-2019-7105Critical· 9.8
7y ago

Adobe XD versions 16.0 and earlier have a path traversal vulnerability

Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

▾ Midnightadobe · xdEPSS 6.2%via NVD
CVE-2018-15982High· 7.8CISA KEV0dayPoC
7y ago

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

▾ Abyssaladobe · flash_playerEPSS 90%via NVD
CVE-2016-4117Critical· 9.8CISA KEVPoC⚖ disputed
10y ago

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

▾ Hadaladobe · flash_playerEPSS 94%via NVD
CVE-2016-1019Critical· 9.8CISA KEV0day
10y ago

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

▾ Hadaladobe · flash_player_desktop_runtimeEPSS 22%via NVD
CVE-2011-0627High· 8.8⚠ Exploited
15y ago

Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content…

Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content…

▾ Midnightadobe · flash_playerEPSS 5.1%via NVD
CVE-2010-2861Critical· 9.8CISA KEVPoC
16y ago

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2)…

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2)…

▾ Hadaladobe · coldfusionEPSS 100%via NVD
CVE-2010-0188High· 7.8CISA KEVPoC
16y ago

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

▾ Abyssaladobe · acrobatEPSS 88%via NVD
CVE-2009-3960Medium· 6.5CISA KEVPoC
16y ago

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers…

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers…

▾ Midnightadobe · blazedsEPSS 90%via NVD
Adobe vulnerabilities (CVEs) — page 17 · VulnSea