Vulnerabilities in Adobe

4,915 results
Vexday analysis

Com 4.472 CVEs catalogadas e 237 surgidas nos últimos 90 dias, a superfície de ataque do portfólio Adobe apresenta volume expressivo e ritmo contínuo de descobertas. A taxa de exploração ativa — 18 entradas no CISA KEV — está em linha com a média geral do catálogo, mas o EPSS de 0,9999 associado à CVE-2024-34102 indica probabilidade máxima de exploração para essa vulnerabilidade específica, exigindo atenção imediata de equipes de resposta. O tipo de falha mais comum é CWE-79 (Cross-Site Scripting), o que sugere fragilidades persistentes na sanitização de entrada em componentes voltados à renderização de conteúdo. A existência de 30 CVEs com prova de conceito pública, combinada a 105 de severidade crítica, reforça a necessidade de priorização rigorosa no ciclo de patching para produtos Adobe em ambientes expostos.

CVE-2022-27791HIGHAdobe Acrobat Reader DC Font Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 17.8%CVE-2022-27799HIGHAdobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 17.7%CVE-2019-7838ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerabilEPSS 17.4%CVE-2021-39842HIGHAdobe Acrobat Reader DC messageHandler.OnMessage Use-After-Free VulnerabilityEPSS 17.4%CVE-2019-7840ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerabEPSS 17.2%CVE-2025-30294MEDIUMColdFusion | Improper Input Validation (CWE-20)EPSS 17.2%CVE-2025-24434CRITICALAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 17.2%CVE-2019-16469Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitatEPSS 17.2%CVE-2020-24436HIGHAcrobat Pro DC PDF Export Out-Of-Bounds Write Vulnerability Could Lead to Arbitrary Code ExecutionEPSS 17.0%CVE-2023-26359CRITICALAdobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionEPSS 17.0%KEVCVE-2018-12863Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an use after fEPSS 16.9%CVE-2019-8197Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and eEPSS 16.8%CVE-2019-8042Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earEPSS 16.8%CVE-2021-45062HIGHAdobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 16.5%CVE-2018-15956Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounEPSS 16.5%CVE-2018-12875Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounEPSS 16.4%CVE-2018-15927Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounEPSS 16.4%CVE-2018-12866Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounEPSS 16.4%CVE-2018-12874Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounEPSS 16.4%CVE-2018-12857Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounEPSS 16.4%