← Back to Vendors

adobe

Security Vendor Profile

327
Products
512,102
Total CVEs
273,921
Critical
101,616
High
81,939
Medium
54,626
Low

Average CVSS Score

5.65

Top Products by CVE Count

acrobat_dc
512 Critical 942 CVEs
acrobat_dc
442 Critical 900 CVEs
acrobat_dc
506 Critical 883 CVEs
acrobat_dc
506 Critical 883 CVEs
acrobat_dc
506 Critical 883 CVEs
acrobat_dc
506 Critical 883 CVEs
acrobat_dc
506 Critical 883 CVEs
acrobat_dc
506 Critical 883 CVEs
acrobat_dc
506 Critical 883 CVEs
acrobat_dc
506 Critical 883 CVEs

Recent CVEs

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose se...

Published: Apr 14, 2026

5.5

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to discl...

Published: Apr 14, 2026

5.5

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to ...

Published: Apr 14, 2026

6.3

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context...

Published: Apr 14, 2026

7.8

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. E...

Published: Apr 14, 2026

7.8

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. E...

Published: Apr 14, 2026

7.8

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this...

Published: Apr 14, 2026

7.8

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure...

Published: Apr 14, 2026

7.8

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation o...

Published: Apr 14, 2026

7.8

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue...

Published: Apr 14, 2026

7.8

CVSS

Product: framemaker

Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the appl...

Published: Apr 14, 2026

8.6

CVSS

Product: incopy

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this iss...

Published: Apr 14, 2026

7.8

CVSS

Product: coldfusion

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature ...

Published: Apr 14, 2026

7.7

CVSS

Product: coldfusion

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could ex...

Published: Apr 14, 2026

2.4

CVSS

Product: coldfusion

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could ex...

Published: Apr 14, 2026

2.4

CVSS

Product: coldfusion

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker re...

Published: Apr 14, 2026

8.4

CVSS

Product: coldfusion

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system...

Published: Apr 14, 2026

8.6

CVSS

Product: coldfusion

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitatio...

Published: Apr 14, 2026

9.3

CVSS

Product: coldfusion

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability...

Published: Apr 14, 2026

7.5

CVSS

Product: incopy

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An...

Published: Apr 14, 2026

7.8

CVSS

Product: bridge

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of ...

Published: Apr 14, 2026

7.8

CVSS

Product: illustrator

Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of thi...

Published: Apr 14, 2026

7.8

CVSS

Product: bridge

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of ...

Published: Apr 14, 2026

7.8

CVSS

Product: bridge

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of ...

Published: Apr 14, 2026

7.8

CVSS

Product: bridge

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of ...

Published: Apr 14, 2026

7.8

CVSS

Product: bridge

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of ...

Published: Apr 14, 2026

7.8

CVSS

Product: photoshop

Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure....

Published: Apr 14, 2026

7.8

CVSS

Product: bridge

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the ap...

Published: Apr 14, 2026

5.5

CVSS

Product: experience_manager

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environm...

Published: Apr 14, 2026

5.4

CVSS

Product: experience_manager_screens

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environm...

Published: Apr 14, 2026

5.4

CVSS

Product: experience_manager

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environm...

Published: Apr 14, 2026

5.4

CVSS

Product: experience_manager_screens

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environm...

Published: Apr 14, 2026

5.4

CVSS

Product: experience_manager

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environm...

Published: Apr 14, 2026

5.4

CVSS

Product: experience_manager_screens

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environm...

Published: Apr 14, 2026

5.4

CVSS

Product: experience_manager

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environm...

Published: Apr 14, 2026

5.4

CVSS

Product: experience_manager_screens

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environm...

Published: Apr 14, 2026

5.4

CVSS

Product: dng_software_development_kit

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to corrupt ...

Published: Apr 14, 2026

5.5

CVSS

Product: acrobat

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability ...

Published: Apr 14, 2026

6.3

CVSS

Product: acrobat_dc

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability ...

Published: Apr 14, 2026

6.3

CVSS

Product: acrobat_reader_dc

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability ...

Published: Apr 14, 2026

6.3

CVSS

Product: acrobat

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability ...

Published: Apr 14, 2026

8.6

CVSS

Product: acrobat_dc

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability ...

Published: Apr 14, 2026

8.6

CVSS

Product: acrobat_reader_dc

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability ...

Published: Apr 14, 2026

8.6

CVSS

Product: indesign

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to discl...

Published: Apr 14, 2026

5.5

CVSS

Product: indesign

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerabi...

Published: Apr 14, 2026

5.5

CVSS

Product: indesign

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory str...

Published: Apr 14, 2026

7.8

CVSS

Product: indesign

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this...

Published: Apr 14, 2026

7.8

CVSS

Product: indesign

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploita...

Published: Apr 14, 2026

7.8

CVSS

Product: acrobat

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could res...

Published: Apr 11, 2026

8.6

CVSS

Product: acrobat_dc

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could res...

Published: Apr 11, 2026

8.6

CVSS